Combofix Download

Download Combofix for Free

  • Download link (ComboFix.exe), IMPORTANT : ComboFix is extremely powerful , You should not run
  • ComboFix.exe unless you are asked to by a trained helper .

    Other Malware Removal Tools

    • Spybot Search & Destroy - Download
    • HijackThis - a product by TrendMicro™ - Download (IMPORTANT: HijackThis does not determine what is good or bad. Do not make any changes to your computer settings unless you are an expert computer user.)

    © ComboFix All rights reserved. This program was created by sUBs License: Freeware .

    Tuesday, March 30, 2010

    Certified Definitions - Detections Added

    Please refer to the table(s) below for a complete listing of threats detected in the latest certified definitions.
    Symantec Security Response Survey: Tell us what you think and you could win $50 from Amazon.com.

    Certified Defs created Certified Defs released Defs Version Extended Defs Version Sequence Number Total Detections
    3/29/2010 3/29/2010 120329b 3/29/2010 rev. 2 109059 6872729
    Detections modified for this release (159):
    Threat Severity Type Discovered
    Adware.180Search
    Adware
    Adware.Adhelper
    Dialer Adware
    Adware.Adlogix
    Adware
    Adware.Aurora
    Adware
    Adware.BargainBuddy
    Adware
    Adware.Begin2search
    Adware
    Adware.BetterInternet
    Adware
    Adware.BlazeFind
    Adware
    Adware.CDT
    Adware
    Adware.CWSIEFeats
    Adware
    Adware.ClearSearch
    Adware
    Adware.CommonName
    Adware
    Adware.Cydoor
    Adware
    Adware.DealHelper
    Adware
    Adware.DelFin
    Adware
    Adware.Istbar
    Adware
    Adware.Lop
    Adware
    Adware.Margoc
    Adware
    Adware.Mycashbag
    Adware
    Adware.Purityscan
    Adware
    Adware.Rugo
    Adware
    Adware.SafeSearch
    Adware
    Adware.SystemProcess
    Adware
    Adware.Tbon
    Adware
    Adware.Topantispyware
    Adware
    Adware.VirtuMonde
    Adware
    Adware.Websearch
    Adware
    AntiVirus2010
    Misleading Application
    Backdoor.Asylum Trojan Horse 05/02/2000
    Backdoor.Beasty Trojan Horse 01/17/2003
    Backdoor.Beasty.G Trojan Horse 07/31/2003
    Backdoor.Bifrose

    Backdoor.CVM Trojan Horse 04/10/2006
    Backdoor.Ciadoor

    Backdoor.ConstructKit
    Trojan Horse 09/10/2002
    Backdoor.EggDrop Trojan Horse 04/10/2003
    Backdoor.Formador
    12/10/2003
    Backdoor.Graybird Trojan Horse 04/02/2003
    Backdoor.Graybird!Gen Trojan 05/11/2007
    Backdoor.Graybird.D Trojan Horse 06/27/2003
    Backdoor.Graybird.G Trojan Horse 09/14/2003
    Backdoor.HackDefender Trojan Horse 03/12/2003
    Backdoor.Haxdoor Trojan Horse 11/30/2003
    Backdoor.IRC.Bot Trojan Horse 05/02/2003
    Backdoor.Kavar Trojan Horse 08/08/2002
    Backdoor.Lithium Trojan Horse 06/03/2002
    Backdoor.NetCrack
    Trojan Horse 08/28/2002
    Backdoor.NetDevil Trojan Horse 02/13/2002
    Backdoor.Papi Trojan Horse 08/16/2006
    Backdoor.Prorat Trojan Horse 06/13/2003
    Backdoor.Ranky Trojan Horse 08/26/2003
    Backdoor.Roxe Trojan Horse 09/27/2004
    Backdoor.Sdbot Trojan Horse 04/30/2002
    Backdoor.Shellbot Trojan Horse 06/03/2005
    Backdoor.Tidserv Worm 09/18/2008
    Backdoor.Trojan Trojan 02/11/1999
    Dialer.Generic
    03/29/2005
    DonaldD.Trojan Trojan Horse 09/28/1999
    Downloader Trojan Horse 06/08/2001
    Downloader.Diliv Trojan 07/15/2008
    Downloader.Goobiz Trojan 04/30/2007
    Downloader.MisleadApp Trojan 06/11/2007
    Downloader.Trojan Trojan Horse 04/04/2002
    Favorit
    Potentially Unwanted App
    Hacktool Trojan 08/17/2001
    Hacktool.AntiAV

    Hacktool.Flooder Trojan 02/20/2007
    Hacktool.LsassSba Trojan Horse 04/27/2004
    Hacktool.Rootkit Trojan Horse 09/27/2001
    Hacktool.Spammer Trojan 10/09/2002
    Infostealer Trojan 12/08/1997
    Infostealer.Bancos
    07/17/2003
    Infostealer.Bancos.AC Trojan 10/19/2008
    Infostealer.Bancos.gen

    Infostealer.Banker.C Trojan 04/02/2007
    Infostealer.Banpaes Trojan 10/14/2003
    Infostealer.Bzup Trojan Horse 08/03/2006
    Infostealer.Eyoni Trojan Horse 09/03/2004
    Infostealer.Gampass Trojan 11/12/2006
    Infostealer.JiangHu Trojan Horse 06/28/2006
    Infostealer.Lemir.Gen Trojan Horse 05/28/2003
    Infostealer.Lineage Trojan Horse 01/11/2005
    Infostealer.Stealth2

    Infostealer.Wowcraft Trojan Horse 07/30/2005
    Joke Program

    SecurityRisk.Downldr
    Other
    Spyware.Ardakey
    Spyware
    Spyware.ISearch
    Spyware
    Spyware.Keylogger
    Spyware
    Spyware.Perfect
    Spyware
    Spyware.RemPSteal
    Spyware
    Spyware.SpyAssault
    Spyware
    SpywareStrike
    Misleading Application
    Trojan Horse Trojan 02/19/2004
    Trojan.Abwiz Trojan Horse 04/23/2005
    Trojan.Adclicker Trojan Horse 09/12/2002
    Trojan.Anserin Trojan Horse 11/23/2005
    Trojan.Ascesso Trojan 08/28/2007
    Trojan.Asprox Trojan 06/08/2007
    Trojan.Blusod Trojan 06/27/2008
    Trojan.Cinmeng Trojan Horse 12/27/2006
    Trojan.Cymdos Trojan 05/16/2008
    Trojan.Danmec Trojan Horse 11/22/2005
    Trojan.Daum Trojan Horse 12/13/2006
    Trojan.Desktophijack

    Trojan.Dropper Trojan Horse 02/02/2000
    Trojan.Duntek Trojan 10/25/2006
    Trojan.FakeAV Trojan 10/10/2007
    Trojan.Favadd Trojan Horse 11/24/2004
    Trojan.Galapoper.A Trojan Horse 04/20/2006
    Trojan.Gamqowi Trojan Horse 10/20/2005
    Trojan.Gema

    Trojan.Gen Trojan 02/19/2010
    Trojan.Gernid Trojan 08/12/2008
    Trojan.Goldun Trojan Horse 01/07/2005
    Trojan.KillAV Trojan Horse 05/18/1999
    Trojan.Linst

    Trojan.Maliframe!html Trojan 07/10/2007
    Trojan.Mebroot Trojan 01/07/2008
    Trojan.Moo Trojan Horse 09/28/2004
    Trojan.Nebuler Trojan Horse 05/19/2006
    Trojan.PWS.QQPass
    Trojan Horse 05/24/2002
    Trojan.Pandex Trojan 01/05/2007
    Trojan.Peacomm.D Trojan Virus 10/31/2007
    Trojan.Popwin Trojan Horse 11/16/2006
    Trojan.Randsom.A Trojan Horse 05/01/2006
    Trojan.Skintrim Trojan Horse 12/12/2006
    Trojan.Sopiclick Trojan 09/11/2009
    Trojan.Spadenf Trojan 06/22/2009
    Trojan.SpamThru Trojan Horse 11/17/2006
    Trojan.Srizbi Trojan 06/20/2007
    Trojan.Startpage Trojan Horse 01/15/2002
    Trojan.Startpage.G Trojan Horse 08/09/2004
    Trojan.SuperSpider Trojan Horse 09/23/2004
    Trojan.Tooso.R Trojan 06/16/2006
    Trojan.Vundo Trojan 11/20/2004
    Trojan.Zbot Trojan 01/10/2010
    Trojan.Zefarch Trojan 01/27/2009
    Trojan.Zlob
    04/23/2005
    W32.Chir.B@mm
    07/29/2002
    W32.Dedler.Worm Worm 03/09/2004
    W32.Gammima Worm 03/21/2007
    W32.Gammima.AG Worm 08/27/2007
    W32.Hitapop Worm 12/01/2006
    W32.IRCBot Trojan Worm 07/08/2002
    W32.Imaut
    09/18/2006
    W32.Ircbrute Worm 06/20/2008
    W32.Koobface.A Worm 08/03/2008
    W32.Mixor.C@mm Worm Virus 10/31/2006
    W32.Mixor.Q@mm Worm 12/29/2006
    W32.Music.Worm.gen

    W32.Mydoom.A@mm Worm 01/26/2004
    W32.Mydoom.L@mm Worm 07/19/2004
    W32.Rontokbro@mm
    09/23/2005
    W32.SillyFDC Worm 01/04/2010
    W32.SillyIM Worm 07/14/2005
    W32.Spybot.Worm Worm 08/09/2007
    XPAntivirus
    Misleading Application
    v2px.1256b

    āļ—āļ”āļŠāļ­āļšāļ”ูāļ§่āļēāđ€āļ„āļĢื่āļ­āļ‡āļ„ุāļ“āļ•ิāļ”āđ„āļ§āļĢัāļŠ Conflicker āļŦāļĢืāļ­āđ„āļĄ่ ?

    āļŦāļĨัāļ‡āļˆāļēāļāļ—ี่āđ„āļ”้āļ­ัāļžāđ€āļ”āļ•āļ‚่āļēāļ§āđ€āļี่āļĒāļ§āļัāļš Conficker āļĄāļēāļ­āļĒ่āļēāļ‡āļ•่āļ­āđ€āļ™ื่āļ­āļ‡āļ•ั้āļ‡āđāļ•่āļ§ัāļ™āļ—ี่ 1 āđ€āļĄāļĐāļēāļĒāļ™ āļ—ี่āļœ่āļēāļ™āļĄāļē āļĨ่āļēāļŠุāļ”āļŦāļ™āļ­āļ™āļĢ้āļēāļĒāļ”ัāļ‡āļāļĨ่āļēāļ§āļ—ี่āđ„āļ”้āđāļžāļĢ่āļāļĢāļ°āļˆāļēāļĒāđ„āļ›āļĒัāļ‡āļ„āļ­āļĄāļžิāļ§āđ€ āļ•āļ­āļĢ์āļ—ั่āļ§āđ‚āļĨāļāļžāļĒāļēāļĒāļēāļĄāđāļˆāļāļˆ่āļēāļĒāđ‚āļ›āļĢāđāļāļĢāļĄāđāļ­āļ™āļ•ี้āđ„āļ§āļĢัāļŠāļŦāļĨāļ­āļāđ€āļŦāļĒื่āļ­āļ§่āļē āļ•āļĢāļ§āļˆāļžāļš Conficker (āļ„āļ§āļēāļĄāļˆāļĢิāļ‡āļ็āļ„ืāļ­āļ•ัāļ§āļĄัāļ™āđ€āļ­āļ‡āļ™ั่āļ™āļĨ่āļ°) āļŦāļēāļāđƒāļŦ้āļ•้āļ­āļ‡āļāļēāļĢāļāļģāļˆัāļ”āļˆāļ°āļ•้āļ­āļ‡āļˆ่āļēāļĒāļ„่āļēāļšāļĢิāļāļēāļĢ 50 āđ€āļŦāļĢีāļĒāļāļŊ (āļ›āļĢāļ°āļĄāļēāļ“ 1,800 āļšāļēāļ—) āļ‹ึ่āļ‡āđ€āļ›็āļ™āđ€āļĢื่āļ­āļ‡āļŦāļĨāļ­āļāļ—ั้āļ‡āļ™ั้āļ™



    āļ„ุāļ“ āļœู้āļ­่āļēāļ™āļŦāļĨāļēāļĒāļ„āļ™ āļŠāļ‡āļŠัāļĒāļ§่āļē āđ€āļ„āļĢื่āļ­āļ‡āļ„āļ­āļĄāļžิāļ§āđ€āļ•āļ­āļĢ์āđ‚āļ”āļ™āđ„āļ§āļĢัāļŠāļ”ัāļ‡āļāļĨ่āļēāļ§āđ€āļĨ่āļ™āļ‡āļēāļ™ āļŦāļĢืāļ­āđ„āļĄ่? āļ‹ึ่āļ‡āļ„āļ§āļēāļĄāļˆāļĢิāļ‡āļ—āļēāļ‡āđ€āļ§็āļšāđ„āļ‹āļ•์āļ็āđ„āļ”้āļ­ัāļžāđ€āļ”āļ•āļ§ิāļ˜ีāļ•āļĢāļ§āļˆāļŠāļ­āļšāļ‡่āļēāļĒāđ† āđ„āļ›āđāļĨ้āļ§ āļ™ั่āļ™āļ„ืāļ­ āļ™ั่āļ™āļ„ืāļ­ āļŦāļēāļāđ€āļ§็āļšāđ„āļ‹āļ•์āļ‚āļ­āļ‡āļ„ุāļ“āđ„āļĄ่āļŠāļēāļĄāļēāļĢāļ–āđ€āļ‚้āļēāđ„āļ›āļĒัāļ‡āđ€āļ§็āļšāđ„āļ‹āļ•์āļœู้āđ€āļŠี่ āļĒāļ§āļŠāļēāļāļĢāļ°āļšāļšāļĢัāļāļĐāļēāļ„āļ§āļēāļĄāļ›āļĨāļ­āļ”āļ ัāļĒāđ„āļ”้ āļ­āļĒ่āļēāļ‡āđ€āļŠ่āļ™ Trend Micro, McAfee, Symantec āđ€āļ›็āļ™āļ•้āļ™ āđ€āļĄื่āļ­āļ§āļēāļ™āļ™ี้āļ—āļēāļ‡āļŠāļģāļ™ัāļāļ‚่āļēāļ§ ABC āđ„āļ”้āđ€āļœāļĒāđāļžāļĢ่āļ‚่āļēāļ§āļ™ี้ āļžāļĢ้āļ­āļĄāļ—ั้āļ‡āđƒāļŦ้āļ„āļģāđāļ™āļ°āļ™āļģāđƒāļ™āļāļēāļĢāļ•āļĢāļ§āļˆāļŠāļ­āļšāļœ่āļēāļ™āļŦāļ™้āļēāđ€āļ§็āļš Coficker Eye Chart āđ‚āļ”āļĒ āđāļŠāļ”āļ‡āļ āļēāļžāđ„āļ­āļ„āļ­āļ™ 6 āļ āļēāļžāļ”ัāļ‡āļĢูāļ›āļ‚้āļēāļ‡āļĨ่āļēāļ‡ āļ‹ึ่āļ‡āļŦāļēāļāļšāļĢāļēāļ§āđ€āļ‹āļ­āļĢ์āļŠāļēāļĄāļēāļĢāļ–āđāļŠāļ”āļ‡āļ āļēāļžāđ„āļ”้āļ„āļĢāļšāļ–้āļ§āļ™ āđāļŠāļ”āļ‡āļ§่āļē āđ„āļĄ่āđ‚āļ”āļ™āļŦāļ™āļ­āļ™āđ„āļ§āļĢัāļŠāđ€āļĨ่āļ™āļ‡āļēāļ™ āđāļ•่āļ–้āļēāļ āļēāļžāļ”้āļēāļ™āļšāļ™āļŦāļēāļĒāđ„āļ›āļŦāļĄāļ” āļŦāļĢืāļ­āļšāļēāļ‡āļŠ่āļ§āļ™ āđāļŠāļ”āļ‡āļ§่āļē āđ‚āļ”āļ™āļŦāļ™āļ­āļ™āđ€āļĨ่āļ™āļ‡āļēāļ™āđ€āļ‚้āļēāđāļĨ้āļ§ āđāļ•่āļ–้āļēāđ„āļĄ่āļĄีāļ āļēāļžāļ‚ึ้āļ™āđ€āļĨāļĒ āļĨāļ­āļ‡āļ•āļĢāļ§āļˆāļŠāļ­āļšāļ่āļ­āļ™āļ§่āļē āļšāļĢāļēāļ§āđ€āļ‹āļ­āļĢ์āļ–ูāļāļāļģāļŦāļ™āļ”āđ„āļĄ่āđƒāļŦ้āđāļŠāļ”āļ‡āļ āļēāļžāđƒāļ™āļŦāļ™้āļēāđ€āļ§็āļš āļŦāļĢืāļ­āđ€āļ›āļĨ่āļē? āļĒัāļ‡āđ„āļ‡āļ็āļĨāļ­āļ‡āļ—āļ”āļŠāļ­āļšāļ”ูāļ™āļ°āļ„āļĢัāļš

    Credit :
    http://www.thaicybergames.com/webboard/index.php?topic=105598.0


    Conficker Eye Chart

    How to interpret:

    If you see this above:It probably means this:
    All images displayed= Normal/Not Infected by Conficker (or using proxy)
    Security/AV logos not displayed= Possibly Infected by Conficker (C variant or greater)
    Some security/AV logos not displayed= Possibly Infected by Conficker A/B variant
    No images displayed= Image loading turned off in browser?
    Any other combination= Poor Internet connection?

    Explanation:

    Conficker (aka Downadup, Kido) is known to block access to over 100 anti-virus and security websites.

    If you are blocked from loading the remote images in the first row of the top table above (AV/security sites) but not blocked from loading the remote images in the second row (websites of alternative operating systems) then your Windows PC may be infected by Conficker (or some other malicious software).

    If you can see all six images in both rows of the top table, you are either not infected by Conficker, or you may be using a proxy server, in which case you will not be able to use this test to make an accurate determination, since Conficker will be unable to block you from viewing the AV/security sites.

    āļ§ีāļ˜ีāļ”ูāļ§่āļēāđ€āļ„āļĢื่āļ­āļ‡āļ•ิāļ”āđ„āļ§āļĢัāļŠ

    āļ­āļēāļāļēāļĢāļ‚āļ­āļ‡ āļ„āļ­āļĄāļžิāļ§āđ€āļ•āļ­āļĢ์āļ—ี่āļšāļ­āļāļ§่āļēāļ•ิāļ”āđ„āļ§āļĢัāļŠ

    1.āđƒāļŠ้āđ€āļ§āļĨāļēāļ™āļēāļ™ āļœิāļ”āļ›āļāļ•ิāđƒāļ™āļāļēāļĢāđ€āļĢีāļĒāļāđ‚āļ›āļĢāđāļāļĢāļĄāļ‚ึ้āļ™āļĄāļēāļ—āļģāļ‡āļēāļ™

    2.āļ‚āļ™āļēāļ”āļ‚āļ­āļ‡ āđ‚āļ›āļĢāđāļāļĢāļĄāđƒāļŦāļ่āļ‚ึ้āļ™

    3.āļ§ัāļ™āđ€āļ§āļĨāļēāļ‚āļ­āļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāđ€āļ›āļĨี่āļĒāļ™āđ„āļ›

    4.āļ‚้āļ­āļ„āļ§āļēāļĄāļ—ี่āļ›āļāļ•ิāđ„āļĄ่āļ„่āļ­āļĒāđ„āļ”้āđ€āļŦ็āļ™āļāļĨัāļšāļ–ูāļāđāļŠāļ”āļ‡āļ‚ึ้āļ™āļĄāļēāļš่āļ­āļĒāđ†

    5.āđ€āļิāļ”āļ­ัāļāļĐāļĢāļŦāļĢืāļ­āļ‚้āļ­āļ„āļ§āļēāļĄāļ›āļĢāļ°āļŦāļĨāļēāļ”āļšāļ™āļŦāļ™้āļēāļˆāļ­

    6.āđ€āļ„āļĢื่āļ­āļ‡āļŠ่āļ‡āđ€āļŠีāļĒāļ‡āļ­āļ­āļāļ—āļēāļ‡āļĨāļģāđ‚āļžāļ‡āđ‚āļ”āļĒāđ„āļĄ่āđ„āļ”้āđ€āļิāļ”āļˆāļēāļāđ‚āļ›āļĢāđāļāļĢ āļĄāļ—ี่āđƒāļŠ้āļ­āļĒู่

    7.āđāļ›้āļ™āļžิāļĄāļž์āļ—āļģāļ‡āļēāļ™āļœิāļ”āļ›āļāļ•ิāļŦāļĢืāļ­āđ„āļĄ่āļ—āļģāļ‡āļēāļ™āđ€āļĨāļĒ

    8.āļ‚āļ™āļēāļ”āļ‚āļ­āļ‡āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāļ—ี่āđ€āļŦāļĨืāļ­āļĨāļ”āļ™้āļ­āļĒāļāļ§่āļēāļ›āļāļ•ิ āđ‚āļ”āļĒāļŦāļēāđ€āļŦāļ•ุāļœāļĨāđ„āļĄ่āđ„āļ”้

    9.āđ„āļŸāļĨ์āđāļŠāļ”āļ‡āļŠāļ–āļēāļ™āļ°āļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ‚āļ­āļ‡āļ”ิāļŠāļ์āļ•ิāļ”āļ„้āļēāļ‡āļ™āļēāļ™āļāļ§่āļēāļ—ี่āđ€āļ„āļĒāđ€āļ›็āļ™

    10.āđ„āļŸāļĨ์āļ‚้āļ­āļĄูāļĨāļŦāļĢืāļ­āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āđ€āļ„āļĒāđƒāļŠ้āļ­āļĒู่ āđ† āļ็āļŦāļēāļĒāđ„āļ›

    11.āđ€āļ„āļĢื่āļ­āļ‡āļ—āļģāļ‡āļēāļ™āļŠ้āļēāļĨāļ‡

    12.āđ€āļ„āļĢื่āļ­āļ‡ āļšูāļ•āļ•ัāļ§āđ€āļ­āļ‡āđ‚āļ”āļĒāđ„āļĄ่āđ„āļ”้āļŠั่āļ‡

    13.āļĢāļ°āļšāļšāļŦāļĒุāļ” āļ—āļģāļ‡āļēāļ™āđ‚āļ”āļĒāđ„āļĄ่āļ—āļĢāļēāļšāļŠāļēāđ€āļŦāļ•ุ

    14.āļĄีāļāļēāļĢ āļĢāļēāļĒāļ‡āļēāļ™āļ§่āļēāļˆāļģāļ™āļ§āļ™āđ€āļ‹āļāđ€āļ•āļ­āļĢ์āļ—ี่āđ€āļŠีāļĒāļĄีāļˆāļģāļ™āļ§āļ™ āđ€āļžิ่āļĄāļ‚ึ้āļ™āļāļ§่āļēāđāļ•่āļ่āļ­āļ™āđ‚āļ”āļĒāļ—ี่ āļĒัāļ‡āđ„āļĄ่āđ„āļ”้āđƒāļŠ้āđ‚āļ›āļĢāđāļāļĢāļĄāđƒāļ”āđ€āļ‚้āļēāđ„āļ›āļ•āļĢāļ§āļˆāļŦāļēāđ€āļĨāļĒ…..

    Are You Infected? Detecting Malware Infection

    The day starts normally. You wake up, drive to work, go to your desk, turn on your computer, take a sip from your coffee, and proceed to check your email. Reminders here, spam there, pictures here, stories there, a couple of games, and some animation. Classify your mail: work related here, from friends, families and acquaintances there. Then you take your morning break.

    Break is over so you get back to your computer and suddenly notice that it is busy with something you are not aware of. So you decide to close all applications, one at a time, and try to figure out what is going on. Then you notice that closing applications is slower than usual.

    You get nervous and then think that it is best to restart your system. Perhaps restarting would bring things back to normal. As your computer boots up, nothing seems to have changed. You log on to it and then find that everything is back to normal. Tension naturally eases up but then you ask yourself, "What could have caused the earlier malfunction? Is my computer infected?"

    When users suspect that a malware has caused a system problem, they are usually wrong nine out of ten times. There are a lot of reasons for a system to malfunction. It is always assumed, however, that a malfunction is caused by something external to a system, something that has the intention and the effect of disrupting the normal system operation, something that is related to a virus or malware. Most of the time, however, the cause of a malfunction is not in any way related to malware.

    Discussing all causes of system malfunction is not easy due to the diversity of systems in terms of hardware, software, firmware, and other configurations. The end of a discussion about one system usually opens discussions about other systems. It is then reasonable that we discuss here how a malware causes systems to malfunction. Once in a while, malware tends to introduce technological innovations but the approaches and concepts remain the same.

    Malware Strategy and Tactics

    It is only apt to discuss the strategy of a malware. First, a malware causes unusual behavior on a system. It may have been designed to propagate, as in the case of viruses, or to inflict havoc or damage on a system, which is what trojans actually do. Other types of malware such as droppers introduce other malware to systems. Virus kits generate malware for other malicious purposes on a system.

    So, what are some of the tactics that various malware employ. Malware is designed to execute on a system. For this to happen, the malware is often packaged in interesting forms such as games, cool animation, and often as pornographic movies or images. Since it cannot get onto a system without user intervention, it uses any means necessary to fool the victim end user into executing its file on their system. Most of the safe computing tips suggest that any new file or attachment should always be scanned before it is executed or opened.

    Once executed, malware can perform its intended malicious function on a system. Unfortunately, it may not always be apparent to users that their system is indeed infected. The remainder of this article will discuss how to determine whether or not the system has been infected and will offer some tips on to manually disinfect the system.

    Memory Residency

    Memory-resident programs are those that can be placed in, and remain in, an affected system's main memory space after execution. Memory residency enables a piece of malware to be readily available whenever needed, ensuring that the malware is easily accessible or can monitor every event on an affected system. This is a malware's way of controlling every activity on an affected system when a condition is satisfied.

    To find out if a malware is resident in the memory, you may need to invoke system tools like the Task Manager in Windows NT-based systems. On Windows 95- or 98-based systems, you can press CTRL-ALT-DEL, which displays a window containing all the running processes in memory. Once you have full view of the things that are currently in memory, check if a malware is there or not.

    This is tricky and at the same time risky. Terminating a memory-resident program that is critical to a system may cause some undesirable results, such as displaying the Blue Screen of Death or even triggering the system to restart. It is advisable to check if a specific memory-resident program is indeed alien to the system, which is not an easy task. You can either consult your operating system manual or search for that program in an Internet search engine. If the search returns no results or does not indicate a relation to any recent malware, it is best that you leave it alone. This is rather too risky to tinker with but may be used for checking if worst comes to worst.

    Spoofed Process Names

    Contemporary malware tends to use process names that look strikingly similar to common process names. It's more like spoofing them into a name that you might think is the real thing but its not. For example, WSOCK32.DLL, a common process in memory handling the library of socket functions, can be spoofed as WSOCK33.DLL. Another is KERNE132.dll (notice that the L in KERNEL is actually the number 1) can be mistaken for the real KERNEL32.DLL. Sometimes the names are actually valid but the path is different. The KERNEL32.DLL is always found in the \Windows\System32 directory but some malware puts it in \Windows\System.

    There are other things you can do to check for infection. For example, you can check if a recently executed and supposedly terminated program is still in memory when it should not be. Another indication is when a program appears to have multiple copies of itself in memory even if no application with that name is currently.

    Lastly, if upon closing all applications and checking the memory usage of a certain entry in memory, it is using up almost all the memory resources you may have to check it out. This is particularly true if there is no indication that there is a memory activity for that entry. The memory space may be deemed safe by just viewing but, tinkering with it, like terminating entries, may produce unwanted results. However, if you find out that certain malware is indeed on your system after verifying with the AV vendors' reports, you can terminate the malware in memory and proceed to find out what other things it has added or modified on your system.

    Gaining Control

    Before a malware becomes memory-resident, it needs to be executed first, as mentioned previously. The initial execution, a user executing the file, is only the first step. Malware often employs other techniques to make sure that it is executed at least once in every system session. It does this by putting links to itself in places where the system initializes or pre-configures the Operating System. These are places or configuration files where it is accessed by an Operating System upon startup. For a malware, it is rather important for it to be executed every time and to advocate its aim to be memory resident. What better way to be executed, or to be triggered to reside in memory, than to be executed upon computer startup.

    There are plenty of places where a malware can use this technique. One of the earliest techniques used was to infect the Command Interpreter, more commonly known as command.com. Upon infecting this file, the malware can assure that it gets executed and can reside in memory even before the command interpreter is executed. A malware can also try to accomplish this by adding links to itself in the autoexec.bat or config.sys, which are configuration files used by DOS and even Windows systems on its basic start up scheme.

    Registries

    Contemporary malware has found new ways to position itself on a system and ensure its execution. One way is by adding or modifying Registry entries. The Registry is a repository of system configuration settings and includes links to applications that need to be executed once the system has been established. This is a good place for malware to exploit and this is what we will look at.

    To access the registry, click "Start" then "Run" and then type "Regedit" beside the "Open:" box. This opens the Registry editor. A word of caution, similar to terminating processes in memory, modifying or deleting registry entries can lead to unwanted system problems. Since the registry is the repository of configuration settings, a minor change here can cause your system to not start or boot up properly or sometimes render some applications to be unusable. It is recommended that you follow these instructions with care.

    In the registry editor, you will see that registry keys are organized similarly to the File/Folder structure. The location, \HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\CurrentVersion, contains 3-6 folders that are part of the Autostart Registries as follows:

     "Run" "RunOnce" "RunOnce\Setup" "RunOnceEx" "RunServices" "RunServicesOnce" 

    The applications in these folders are what Windows executes immediately after a system is started up. Another similar location and privilege that may contain these 3-6 Autostart registries are in \HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion

    You may have to check and familiarize yourself with each entry. The total number of entries is different for every system and is often proportional to the number of system tray entries that you have. The system tray is usually located at the lower right section of the Windows desktop and contains small icons beside the clock.

    These applications are usually Windows-based executable files that have an .EXE extension, and are thus assumed that these have File Properties just as typical Windows executables do. You may check each file that is associated in the AutoRun Registry by opening a File Manager (also known as Windows Explorer) to view the file properties of each entry. To do this, right-click the files, choose "Properties", and then check out the entries in the "Version" tab of each file. The "Company" and "Product Version" often tell you a lot about the file. Registry entries in these locations without the full path are located in the Windows Directory, Windows\System, or Windows\System32 Directory. Keep in mind that some malware sets the Hidden file attribute on files it drops on the system. If this is the case, you will have to set Windows Explorer to show hidden files (Tools->Folder Options, click the View tab, then select the Show hidden files and folders radio button).

    If the folders contain unusual entries such as misspelled company names or grammatical errors, then this should give you more reason to investigate that application. Check out some manuals or refer to search engines. If these files are verified as being malicious, then you can start removing their links. Let me remind you again that removing critical entries, by mistake, in the registry produces undesirable results. It is important that you thoroughly examine and verify that the links you will remove from your system are links to a malware file.

    Another way for a malware to gain control of systems is by modifying the association of commonly used file extensions. Windows is typically file extension-based and uses the HKEY_CLASSES_ROOT entries to determine which applications or programs to run for certain extensions. .EXE, .DLL, .COM, and other readily infectable files are commonly modified. These entries or registry keys are often not associated with programs and indicate internal system commands or contain the appropriate applications typically associated with it.

    It is also advisable to back up a registry entry first by exporting its registry key to a file. To do this, right click the folder-like entry in the registry and then select "Export". Agree when prompted to save it to a file. After creating a backup, you can now delete or modify the registry key. If you find that what you deleted is a normal entry and not that of a malware, restore it from your backup.

    Other StartUp locations

    Other areas where AutoStart entries can be found are in the files, System.ini and Win.ini. A malware often modifies these with links to itself added to the "run=" or "load=" sections of the files. These files are located at the Windows Directory (typically C:\Windows).

    Following the same approach that you followed with the registry entries, you can remove them from the AutoStart entries after you have verified that they are malicious. Again, back up these files before making any modification just in case the entries are not malicious and you have to restore the files to their original form.

    All the necessary system configuration files can be accessed, viewed and edited with the Sysedit program. To invoke the program, click "Start", and then "Run", and then type "Sysedit" in the "Open:" box.

    Another place where you can find autostart entries are in the Start > (All) Programs > Startup folder. The entries here are also referenced and are executed immediately after system startup. Similarly, you may need to back up these files before tinkering with them.

    Macros

    Applications like word processing, spreadsheets or PowerPoint presentations are often vulnerable to macro viruses. You can check for malicious activities by checking for macros within these files. To do this, access the macros organizer (you may refer to your applications help file) and check if there are any unknown macros inside, press the ALT-F11 keys in the more recent offerings of Microsoft Office Family (beginning in Office 97 and up). However, some macro viruses tend to hide themselves from users by changing the foreground/background of the macro font display or by adding multiple tabs to make the text invisible to the default view pane.

    The following is an explanation of procedures readers can use for two different applications that use macros: MS Word and Excel.

    MS Word

    Search your hard drive for any file named NORMAL.DOT, which is the global template of this application. Rename it to make sure that you have a backup and this will trigger Word to recreate a new NORMAL.DOT and the assurance that it is clean of any macro viruses. Open Microsoft Word and then turn on the Macro Virus Protection. After which, you may now try and open the file that you suspect has a macro virus. If there are any macros inside these files, you will be prompted by the Macro Virus Protection. It may also help if you can jot down the file size of the NORMAL.DOT so that in the future, you can just refer to this size in comparing it with the existing global template. This way you can easily spot the difference.

    MS Excel

    Search your hard drive for any folder name XLStart. For Excel, this folder contains all the things necessary for customization and this includes macros as well. You can transfer the contents of this folder to a temporary directory. Open Excel and turn on the Macro Virus Protection. After doing so, you can now open the Excel file that may be infected and then the Macro Virus Protection should be able to figure that out for you.

    So What Now?

    Now that you have removed the link to the suspects, you can send your suspected file to your preferred Antivirus Vendor for analysis. You may send it via email and attach the suspected file in a password-protected zip file (don't forget to include the password in the mail so that the zip file can be extracted and analyzed). The vendor's response usually takes a matter of days, depending on your subscription. You can do the same to the files that you have seen in memory and fear to be malicious.

    If after reading this article twice, you still cannot comprehend what has been discussed or is not willing to risk your system to be broken by the modifications suggested, it may be better for you to use an Antivirus software and allow that software to check your system for malicious codes or programs.

    The best ways to keep your system from infection are found in safe computing guides that are available on most AV Vendors' Web sites. These discussions include the basic things you must do to minimize the risk of being infected. Not only are these helpful, they are also a good venue for you to know more about your system and making you a better citizen of Cyberspace.

    āļˆāļ°āļ•āļĢāļ§āļˆāļŠāļ­āļšāđ„āļ”้āļ­āļĒ่āļēāļ‡āđ„āļĢāļ§่āļēāđ€āļ„āļĢื่āļ­āļ‡āļ•ิāļ”āđ„āļ§āļĢัāļŠ

    āļ›ัāļˆāļˆุāļšัāļ™āļ„āļ­āļĄāļžิāļ§āđ€āļ•āļ­āļĢ์āđ€āļ‚้āļēāļĄāļēāļĄีāļšāļ—āļšāļēāļ—āļĄāļēāļāđƒāļ™āļŠีāļ§ิāļ•āļ›āļĢāļ°āļˆāļģāļ§ัāļ™ āđāļ•่āļ—āļĢāļēāļšāļŦāļĢืāļ­āđ„āļĄ่āļ§่āļēāļ ัāļĒāļ„ุāļāļ„āļēāļĄāļ—āļēāļ‡āļ„āļ­āļĄāļžิāļ§āđ€āļ•āļ­āļĢ์āļ็āļĄีāļĄāļēāļāļ‚ึ้āļ™āļ”้āļ§āļĒāđ€āļŠ่āļ™āļัāļ™ āļ ัāļĒāļ„ุāļāļ„āļēāļĄāļ—ี่āļ™่āļēāļāļĨัāļ§āļĄāļēāļāļ—ี่āļŠุāļ”āļ—āļēāļ‡āļŦāļ™ึ่āļ‡āļ็āļ„ืāļ­āļ ัāļĒāļ„ุāļāļ„āļēāļĄāļ—ี่āđ€āļิāļ”āļˆāļēāļāđ„āļ§āļĢัāļŠ āļ„āļ­āļĄāļžิāļ§āđ€āļ•āļ­āļĢ์ āļ‹ึ่āļ‡āļ™ัāļšāļ§ัāļ™āļ็āļĒิ่āļ‡āļ—āļ§ีāļ„āļ§āļēāļĄāļĢุāļ™āđāļĢāļ‡āđƒāļ™āļāļēāļĢāļ—āļģāļĨāļēāļĒāļĄāļēāļāļ‚ึ้āļ™ āđāļĨāļ°āļœู้āđƒāļŠ้āļšāļēāļ‡āļ„āļ™āđ„āļĄ่āļĄีāļ„āļ§āļēāļĄāļĢู้āđƒāļ™āļāļēāļĢāļ•āļĢāļ§āļˆāļŠāļ­āļšāļ§่āļēāđ€āļ„āļĢื่āļ­āļ‡āļ‚āļ­āļ‡āļ•āļ™āļ•ิāļ”āđ„āļ§āļĢัāļŠāļŦāļĢืāļ­āđ„āļĄ่ āļ”้āļ§āļĒāđ€āļŦāļ•ุāļ™ี้āđ€āļ­āļ‡āļœู้āđ€āļ‚ีāļĒāļ™āļˆึāļ‡āđ„āļ”้āđ€āļĢีāļĒāļšāđ€āļĢีāļĒāļ‡āļšāļ—āļ„āļ§āļēāļĄāļ‰āļšัāļšāļ™ี้āļ‚ึ้āļ™ āļšāļ—āļ„āļ§āļēāļĄāļ‰āļšัāļšāļ™ี้āļˆāļ°āļāļĨ่āļēāļ§āļ–ึāļ‡āļĨัāļāļĐāļ“āļ°āļāļēāļĢāļˆู่āđ‚āļˆāļĄāļ•่āļēāļ‡āđ† āļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠ āđāļĨāļ°āļ§ิāļ˜ีāļāļēāļĢāđƒāļ™āļāļēāļĢāļ•āļĢāļ§āļˆāļŠāļ­āļšāļ”ูāļ§่āļēāđ€āļ„āļĢื่āļ­āļ‡āđ€āļĢāļēāļ•ิāļ”āđ„āļ§āļĢัāļŠāļŦāļĢืāļ­āđ„āļĄ่

    āļŦāļĄāļēāļĒāđ€āļŦāļ•ุ āļ„āļģāļ§่āļē Malware āļĄāļēāļˆāļēāļāļ„āļģāļ§่āļē Malicious Software āđ€āļ›็āļ™āđ‚āļ›āļĢāđāļāļĢāļĄāļ›āļĢāļ°āđ€āļ āļ—āļ—ี่āļĄุ่āļ‡āļŦāļ§ัāļ‡āļ—āļģāļĨāļēāļĒāļĢāļ°āļšāļšāļ„āļ­āļĄāļžิāļ§āđ€āļ•āļ­āļĢ์ āļ›āļĢāļ°āļāļ­āļšāļ”้āļ§āļĒāđ„āļ§āļĢัāļŠ āļŦāļ™āļ­āļ™āļ­ิāļ™āđ€āļ—āļ­āļĢ์āđ€āļ™็āļ• āđāļĨāļ°āđ‚āļ—āļĢāļˆัāļ™ āđƒāļ™āļšāļ—āļ„āļ§āļēāļĄāļ™ี้āļˆāļ°āđƒāļŠ้āļ„āļģāļ§่āļē "āđ„āļ§āļĢัāļŠ" āļ‹ึ่āļ‡āđƒāļŦ้āđ€āļ‚้āļēāđƒāļˆāļ•āļĢāļ‡āļัāļ™āļ§่āļēāļŦāļĄāļēāļĒāļ–ึāļ‡ "Malware"

    āđ€āļĢิ่āļĄāļ•้āļ™āļ”้āļ§āļĒāļāļēāļĢāļĻึāļāļĐāļēāļāļĨāļĒุāļ—āļ˜์āļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠ

    āđ€āļ›็āļ™āļ—ี่āļ—āļĢāļēāļšāļัāļ™āļ”ีāļ§่āļēāđ„āļ§āļĢัāļŠāļ„āļ­āļĄāļžิāļ§āđ€āļ•āļ­āļĢ์āļ™ั้āļ™āļĄีāļˆุāļ”āļĄุ่āļ‡āļŦāļĄāļēāļĒāļ—āļģāđƒāļŦ้āļĢāļ°āļšāļšāļ—āļģāļ‡āļēāļ™ āļœิāļ”āļ›āļāļ•ิ āđāļĨāļ°āļ–ูāļāļ­āļ­āļāđāļšāļšāļĄāļēāđƒāļŦ้āļĄีāļ„āļ§āļēāļĄāļŠāļēāļĄāļēāļĢāļ–āđƒāļ™āļāļēāļĢāđāļžāļĢ่āļāļĢāļ°āļˆāļēāļĒāļ•ัāļ§āđ€āļ­āļ‡ āļ”ัāļ‡āļ™ั้āļ™āđ„āļ§āļĢัāļŠāļˆāļ°āļ•้āļ­āļ‡āļĄีāļāļĨāļĒุāļ—āļ˜์āļ•่āļēāļ‡āđ† āđ€āļžื่āļ­āļ—ี่āļˆāļ°āđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ•ัāļ§āđ€āļ­āļ‡āđƒāļ™āļĢāļ°āļšāļšāđ„āļ”้ āļĢูāļ›āđāļšāļšāļ—ี่āļ™่āļēāļŠāļ™āđƒāļˆāļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠāļŠ่āļ§āļ™āļĄāļēāļāļĄัāļāļˆāļ°āļ­āļĒู่āđƒāļ™āļĢูāļ›āļ‚āļ­āļ‡āđ„āļŸāļĨ์āđāļšāļšāļ•่āļēāļ‡āđ† āđ€āļŠ่āļ™ āđ€āļāļĄāļŠ์ āđāļ­āļ™ิāđ€āļĄāļŠั่āļ™ āļ āļēāļžāļŦāļĢืāļ­āļ āļēāļžāļĒāļ™āļ•āļĢ์āļĨāļēāļĄāļāļ­āļ™āļēāļˆāļēāļĢ āđ€āļ›็āļ™āļ•้āļ™ āđƒāļ™āļ›ัāļˆāļˆุāļšัāļ™āđ„āļŸāļĨ์āļ•่āļēāļ‡āđ† āđ€āļŦāļĨ่āļēāļ™ี้āļŠ่āļ§āļ™āđƒāļŦāļ่āļˆāļ°āļĄāļēāđƒāļ™āļĢูāļ›āļ‚āļ­āļ‡āđ„āļŸāļĨ์āļ—ี่āđāļ™āļšāļĄāļēāļัāļšāļ­ี-āđ€āļĄāļĨ์ āđ€āļŦāļĒื่āļ­āļŦāļĢืāļ­āļœู้āđƒāļŠ้āļ—ี่āļ‚āļēāļ”āļ„āļ§āļēāļĄāļĢู้āļŦāļĢืāļ­āļ„āļ§āļēāļĄāļĢāļ°āļĄัāļ”āļĢāļ°āļ§ัāļ‡āļˆāļ°āļĢัāļ™āđ„āļŸāļĨ์āđ€āļŦāļĨ่āļēāļ™ี้āđ‚āļ”āļĒāđ„āļĄ่ āļŠāđāļāļ™āļ•āļĢāļ§āļˆāļŦāļēāđ„āļ§āļĢัāļŠāļ่āļ­āļ™ āļœāļĨāļ—ี่āļ•āļēāļĄāļĄāļēāļ„ืāļ­āđ€āļ„āļĢื่āļ­āļ‡āļ—ี่āđƒāļŠ้āļ‡āļēāļ™āļ­āļĒู่āļ•ิāļ”āđ„āļ§āļĢัāļŠāđ„āļ”้ āđƒāļ™āļŦัāļ§āļ‚้āļ­āļ•่āļ­āđ† āđ„āļ›āļˆāļ°āļāļĨ่āļēāļ§āļ–ึāļ‡āļ§ิāļ˜ีāļāļēāļĢāļ•āļĢāļ§āļˆāļŠāļ­āļšāļ§่āļēāđ€āļ„āļĢื่āļ­āļ‡āļ—ี่āđƒāļŠ้āļ‡āļēāļ™āļ­āļĒู่āļ•ิāļ”āđ„āļ§āļĢัāļŠāļŦāļĢืāļ­āđ„āļĄ่āđāļĨāļ°āļ§ิāļ˜ี āļāļēāļĢāđāļ้āđ„āļ‚āļ­āļĒ่āļēāļ‡āļ‡่āļēāļĒ

    āđ€āļĄื่āļ­āđ„āļ§āļĢัāļŠāļัāļ‡āļ•ิāļ”āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģ

    āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āļัāļ‡āļ•ิāļ”āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģ āļŦāļĢืāļ­ Memory-resident program āđ€āļ›็āļ™āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āļ­āļēāļˆāļˆāļ°āļ–ูāļāļšāļĢāļĢāļˆุ āđāļĨāļ°āļ„้āļēāļ‡āļ­āļĒู่āđƒāļ™āļžื้āļ™āļ—ี่āļ‚āļ­āļ‡āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāļŦāļĨัāļāļ‚āļ­āļ‡āļĢāļ°āļšāļšāļŦāļĨัāļ‡āļˆāļēāļāļ–ูāļāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์ āļ‹ึ่āļ‡āļ–้āļēāđ‚āļ›āļĢāđāļāļĢāļĄāļ”ัāļ‡āļāļĨ่āļēāļ§āđ€āļ›็āļ™āđ‚āļ›āļĢāđāļāļĢāļĄāđ„āļ§āļĢัāļŠāļ™ั้āļ™āļˆāļ°āļ—ิ้āļ‡āļŠ่āļ§āļ™āļ‚āļ­āļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāđ„āļ§āļĢัāļŠāļšāļēāļ‡ āļŠ่āļ§āļ™āđ„āļ§้āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģ āđ€āļžื่āļ­āļ„āļ­āļĒāđ€āļ้āļēāļ”ูāļ§่āļēāļ–้āļēāļĄีāđ€āļŦāļ•ุāļāļēāļĢāļ“์āļ—ี่āļ•āļĢāļ‡āļัāļšāđ€āļ‡ื่āļ­āļ™āđ„āļ‚āļ—ี่āđ„āļ§āļĢัāļŠāļ•ั้āļ‡āđ„āļ§้āļ—āļģāđƒāļŦ้āļŠ่āļ§āļ™ āļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠāđ€āļĢิ่āļĄāļ—āļģāļ‡āļēāļ™āļ•่āļ­āđ„āļ› āđ€āļŠ่āļ™āđ„āļ§āļĢัāļŠāļ—ี่āļĄีāļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ—ุāļāļ§ัāļ™āļ—ี่ 20 āļĄีāļ™āļēāļ„āļĄ (Date Trigger) āļŦāļĢืāļ­āļ—āļģāļ‡āļēāļ™āļ—ุāļāļ„āļĢั้āļ‡āđ€āļĄื่āļ­āļœู้āđƒāļŠ้āļāļ”āļ›ุ่āļĄ "x" āļšāļ™āđāļ›้āļ™āļžิāļĄāļž์ (Key Trigger) āđ€āļ›็āļ™āļ•้āļ™

    āļ§ิāļ˜ีāļāļēāļĢāļ„้āļ™āļŦāļēāļ§่āļēāļĄีāđ‚āļ›āļĢāđāļāļĢāļĄāđ„āļ§āļĢัāļŠāļัāļ‡āļ•ัāļ§āļ­āļĒู่āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāļŦāļĢืāļ­āđ„āļĄ่ āļˆāļģāđ€āļ›็āļ™āļ•้āļ­āļ‡āļ­āļēāļĻัāļĒāđ‚āļ›āļĢāđāļāļĢāļĄ Task Manager āļ—ี่āđ€āļ›็āļ™āđ€āļ„āļĢื่āļ­āļ‡āļĄืāļ­āļ—ี่āļĄāļēāļžāļĢ้āļ­āļĄāļัāļšāļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์āļ—ุāļāđ€āļ§āļ­āļĢ์āļŠัāļ™ āđ‚āļ”āļĒāļ—ี่āļ–้āļēāđ€āļ›็āļ™āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์ 95/98/ME āđƒāļŦ้āļāļ”āļ›ุ่āļĄ Ctrl-Alt-Del āļˆāļ°āđ„āļ”้āļœāļĨāļ”ัāļ‡āļĢูāļ›āļ—ี่ 1 āđāļĨāļ°āļ–้āļēāđ€āļ›็āļ™āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์ NT 2000 āđāļĨāļ° XP āđƒāļŦ้āļ—āļģāļāļēāļĢāļāļ” Ctrl-Shift-Esc āļˆāļ°āđ„āļ”้āļœāļĨāļ”ัāļ‡āļĢูāļ›āļ—ี่ 2 āļˆāļēāļāļ—ั้āļ‡āļŠāļ­āļ‡āļĢูāļ›āļˆāļ°āđ€āļŦ็āļ™āļ§่āļēāđ‚āļ›āļĢāđāļāļĢāļĄ Task Manager āļˆāļ°āđāļŠāļ”āļ‡āļĢāļēāļĒāļŠื่āļ­āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ั้āļ‡āļŦāļĄāļ”āļ—ี่āļĢัāļ™āļ­āļĒู่āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģ āļ”ัāļ‡āļ™ั้āļ™āļ–้āļēāđāļ™่āđƒāļˆāļ§่āļēāđ‚āļžāļĢāđ€āļ‹āļŠāđƒāļ”āđ€āļ›็āļ™āļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠāđāļĨ้āļ§ āļ็āļ—āļģāļāļēāļĢāļĒุāļ•ิāļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ‚āļ­āļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļ™ั้āļ™ āđ‚āļ”āļĒāļāļēāļĢāđ€āļĨืāļ­āļāđ‚āļžāļĢāđ€āļ‹āļŠāļ—ี่āđāļ™่āđƒāļˆāļ§่āļēāđ€āļ›็āļ™āđ„āļ§āļĢัāļŠāđāļĨ้āļ§āļāļ”āļ›ุ่āļĄ End Task āļŠāļģāļŦāļĢัāļšāļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์ 95/98/ME āļŦāļĢืāļ­āļāļ”āļ›ุ่āļĄ End Process āļŠāļģāļŦāļĢัāļšāļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์ NT 2000 āđāļĨāļ° XP

    āļŦāļĄāļēāļĒāđ€āļŦāļ•ุ āļāļēāļĢāļĒุāļ•ิāļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ‚āļ­āļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ี่āđāļ™่āđƒāļˆāļ§่āļēāđ€āļ›็āļ™āđ‚āļžāļĢāđ€āļ‹āļŠāļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠāļ™ั้āļ™āļ็āļ­āļēāļˆāļˆāļ°āļĄีāļ„āļ§āļēāļĄ āđ€āļŠี่āļĒāļ‡āļ—ี่āļˆāļ°āđ€āļิāļ”āļœāļĨāļĨัāļžāļ˜์āļ­ัāļ™āđ„āļĄ่āļžึāļ‡āļ›āļĢāļ°āļŠāļ‡āļ„์ āđ€āļŠ่āļ™ āļāļēāļĢāđ€āļิāļ”āļŦāļ™้āļēāļˆāļ­āļŠีāļŸ้āļē (Blue Screen of Death) āļŦāļĢืāļ­ āļŠ่āļ‡āļœāļĨāđƒāļŦ้āļĢāļ°āļšāļšāļ—āļģāļāļēāļĢāļĢีāļŠāļ•āļēāļĢ์āļ— āđ€āļ›็āļ™āļ•้āļ™ āļ”ัāļ‡āļ™ั้āļ™āļāļēāļĢāļ—ี่āļˆāļ°āđāļ™่āđƒāļˆāļ§่āļēāđ‚āļžāļĢāđ€āļ‹āļŠāļ™ั้āļ™āļ­āļēāļˆāļˆāļ°āļ•้āļ­āļ‡āļ—āļģāļāļēāļĢāļĻึāļāļĐāļēāļˆāļēāļāļ„ู่āļĄืāļ­āļ‚āļ­āļ‡āļĢāļ°āļšāļš āļ›āļิāļšัāļ•ิāļāļēāļĢāļ่āļ­āļ™āļ§่āļēāđ€āļ›็āļ™āđ‚āļžāļĢāđ€āļ‹āļŠāļ‚āļ­āļ‡āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļŦāļĢืāļ­āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āđƒāļŠ้āļ‡āļēāļ™āļ­āļĒู่āļŦāļĢืāļ­ āđ„āļĄ่ āļŦāļĢืāļ­āļ„้āļ™āļŦāļēāļ‚้āļ­āļĄูāļĨāļ‚āļ­āļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļ™ั้āļ™āđ† āđƒāļ™āļ­ิāļ™āđ€āļ—āļ­āļĢ์āđ€āļ™็āļ• āļ–้āļēāļœāļĨāļˆāļēāļāļāļēāļĢāļ„้āļ™āļŦāļēāđ„āļĄ่āļš่āļ‡āļšāļ­āļāļ§่āļēāđ€āļ›็āļ™āđ‚āļžāļĢāđ€āļ‹āļŠāļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠ āļ็āļ„āļ§āļĢāļ—ี่āļˆāļ°āļ›āļĨ่āļ­āļĒāļ—ิ้āļ‡āđ„āļ§้ āđ€āļžื่āļ­āļ›้āļ­āļ‡āļัāļ™āļ„āļ§āļēāļĄāđ€āļŠี่āļĒāļ‡āļ—ี่āļˆāļ°āđ€āļิāļ”āļ‚ึ้āļ™

    āļĢูāļ›āļ—ี่ 1 āđ‚āļ›āļĢāđāļāļĢāļĄ Task Manager āļ‚āļ­āļ‡āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์ 98

    āļĢูāļ›āļ—ี่ 2 āđ‚āļ›āļĢāđāļāļĢāļĄ Task Manager āļ‚āļ­āļ‡āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์ 2000

    āļŠāļĢ้āļēāļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļŦāļĨāļ­āļāļĨāļ§āļ‡

    āđ„āļ§āļĢัāļŠāļˆāļ°āļžāļĒāļēāļĒāļēāļĄāđƒāļŠ้āļŠื่āļ­āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ี่āđ€āļ”่āļ™āđāļĨāļ°āļ„āļĨ้āļēāļĒāđ† āļัāļšāļŠื่āļ­āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ั่āļ§āđ„āļ›āļ—ี่āļ—āļģāļ‡āļēāļ™āļ­āļĒู่āđƒāļ™āđ€āļ„āļĢื่āļ­āļ‡ āđ€āļžื่āļ­āļ—ี่āļˆāļ°āļŦāļĨāļ­āļāđƒāļŦ้āļœู้āđƒāļŠ้āļ—ี่āđ„āļĄ่āļŠัāļ‡āđ€āļāļ•āđ„āļĄ่āļāļĨ้āļēāļ—āļģāļāļēāļĢāļĒุāļ•ิāļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ‚āļ­āļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļ”ัāļ‡ āļāļĨ่āļēāļ§ āļ™ั่āļ™āļ็āļŦāļĄāļēāļĒāļ„āļ§āļēāļĄāļ§่āļēāđ„āļ§āļĢัāļŠāļˆāļ°āļŠāļĢ้āļēāļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļŦāļĨāļ­āļāļĨāļ§āļ‡ (Spoof) āđƒāļŦ้āļĄีāļŠื่āļ­āļ„āļĨ้āļēāļĒāđ† āļัāļšāđ‚āļžāļĢāđ€āļ‹āļŠāļ—ั่āļ§āđ„āļ› āļĒāļāļ•ัāļ§āļ­āļĒ่āļēāļ‡āđ€āļŠ่āļ™ WSOCK32.DLL āđ€āļ›็āļ™āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ั่āļ§āđ† āđ„āļ›āļ—ี่āļ­āļĒู่āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāđ€āļžื่āļ­āđƒāļŠ้ handle library āļ‚āļ­āļ‡āļŸัāļ‡āļ์āļŠั่āļ™āļ‹็āļ­āļāđ€āļ็āļ• āđāļĨāļ°āļ–ูāļāđ€āļ›āļĨี่āļĒāļ™āļŠื่āļ­āđ€āļ›็āļ™ WSOCK33.DLL āļ­ีāļāļ•ัāļ§āļ­āļĒ่āļēāļ‡āđ€āļ›็āļ™āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ี่āđ„āļ§āļĢัāļŠāļĄัāļāđƒāļŠ้āļŦāļĨāļ­āļāļĨāļ§āļ‡āļĄāļēāļāļ„ืāļ­ KERNEL32.DLL āđ€āļ›āļĨี่āļĒāļ™āļŠื่āļ­āđ€āļ›็āļ™ KERNE132.DLL (āļŠัāļ‡āđ€āļāļ•āļ§่āļēāļ•ัāļ§ L āļ‚āļ­āļ‡āļ„āļģāļ§่āļē KERNEL āļ–ูāļāđ€āļ›āļĨี่āļĒāļ™āđ€āļ›็āļ™āđ€āļĨāļ‚ 1) āđāļ•่āđƒāļ™āļšāļēāļ‡āļ„āļĢั้āļ‡āļ็āļĄีāđ„āļ§āļĢัāļŠāļšāļēāļ‡āļ•ัāļ§āļŠāļĢ้āļēāļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ี่āļĄีāļŠื่āļ­āđ‚āļžāļĢāđ€āļ‹āļŠāđ€āļŦāļĄืāļ­āļ™āļัāļ™āđāļ•่āđ€āļ็āļš āđ„āļ§้āļ—ี่āļ•āļģāđāļŦāļ™่āļ‡āļ•่āļēāļ‡āļัāļ™ (path āļ•่āļēāļ‡āļัāļ™) āđ€āļŠ่āļ™ KERNEL32.DLL āļ›āļāļ•ิāļˆāļ°āļ–ูāļāđ€āļ็āļšāđ„āļ§้āđƒāļ™āđ„āļ”āđ€āļĢāļāļ—āļ­āļĢี่ %Windows\System32% āđāļ•่āđ„āļ§āļĢัāļŠāļšāļēāļ‡āļ•ัāļ§āļˆāļ°āļŠāļĢ้āļēāļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļŠื่āļ­āđ€āļ”ีāļĒāļ§āļัāļ™āļ™ี้āđ€āļ็āļšāđ„āļ§้āđƒāļ™āđ„āļ”āđ€āļĢāļāļ—āļ­āļĢี่ %Windows\System% āļ็āđ€āļ›็āļ™āđ„āļ”้

    āļ­ีāļāļŦāļ™ึ่āļ‡āļ§ิāļ˜ีāļ—ี่āđƒāļŠ้āļ•āļĢāļ§āļˆāļŠāļ­āļšāļŦāļēāđ‚āļžāļĢāđ€āļ‹āļŠāļŦāļĨāļ­āļāļĨāļ§āļ‡āļ็āļ„ืāļ­ āļ•āļĢāļ§āļˆāļŠāļ­āļšāđ‚āļžāļĢāđ€āļ‹āļŠāļ—ี่āļĒัāļ‡āļ„āļ‡āļ—āļģāļ‡āļēāļ™āļ„้āļēāļ‡āļ­āļĒู่āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāļ”้āļ§āļĒāļ§ิāļ˜ีāļ”ัāļ‡āļ—ี่āđ„āļ”้āļāļĨ่āļēāļ§āļĄāļē āđƒāļ™āļŦัāļ§āļ‚้āļ­āļ—ี่āļœ่āļēāļ™āļĄāļēāđāļĨ้āļ§ āļ­āļēāļāļēāļĢāļ—ี่āļš่āļ‡āļšāļ­āļāļ§่āļēāđ€āļ„āļĢื่āļ­āļ‡āđ„āļ”้āļ•ิāļ”āđ„āļ§āļĢัāļŠāđāļĨ้āļ§āļ็āļ„ืāļ­āđ€āļĄื่āļ­āļĄีāđ‚āļ›āļĢāđāļāļĢāļĄāļ—āļģāļ‡āļēāļ™āđāļĨ้āļ§ āđ‚āļ›āļĢāđāļāļĢāļĄāļ—āļģāļāļēāļĢāļ„ัāļ”āļĨāļ­āļāļ•ัāļ§āđ€āļ­āļ‡āļĄāļēāļāļĄāļēāļĒāđƒāļŦ้āļ—āļģāļ‡āļēāļ™āļ­āļĒู่āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģ āļ–ึāļ‡āđāļĄ้āļ§่āļēāđƒāļ™āļ‚āļ“āļ°āļ™ั้āļ™āđ„āļĄ่āļĄีāđ‚āļ›āļĢāđāļāļĢāļĄāļ”ัāļ‡āļāļĨ่āļēāļ§āļ—āļģāļ‡āļēāļ™āļ­āļĒู่āđ€āļĨāļĒ

    āļ–้āļēāļ•āļĢāļ§āļˆāļŠāļ­āļšāļāļēāļĢāđƒāļŠ้āļ‡āļēāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģ āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āđ€āļ›็āļ™āļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠāļŠ่āļ§āļ™āđƒāļŦāļ่āļˆāļ°āđƒāļŠ้āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāđ€āļืāļ­āļšāļ—ั้āļ‡āļŦāļĄāļ”āļ—ี่āļĄี āđāļ•่āļ–้āļēāđ„āļĄ่āļ›āļĢāļēāļāļāļ­āļēāļāļēāļĢāļ”ัāļ‡āļāļĨ่āļēāļ§āļ็āļĄั่āļ™āđƒāļˆāđ„āļ”้āļ­ีāļāļĢāļ°āļ”ัāļšāļŦāļ™ึ่āļ‡āļ§่āļēāđ„āļĄ่āļĄีāđ„āļ§āļĢัāļŠāļ—ี่āļ—āļģāļ‡āļēāļ™ āđƒāļ™āđ€āļ„āļĢื่āļ­āļ‡āļ‚āļ“āļ°āļ™ี้

    āļ„āļ§āļšāļ„ุāļĄāļāļēāļĢāļāļĢāļ°āļˆāļēāļĒāļ•ัāļ§

    āļˆāļēāļāļ—ี่āđ„āļ”้āļāļĨ่āļēāļ§āļĄāļēāđƒāļ™āļŦัāļ§āļ‚้āļ­āļ่āļ­āļ™āļŦāļ™้āļēāļ™ี้āđāļĨ้āļ§ āļāļēāļĢāļ—ี่āđ„āļ§āļĢัāļŠāļˆāļ°āļัāļ‡āļ•ัāļ§āļĨāļ‡āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāđ„āļ”้āļ™ั้āļ™ āļˆāļģāđ€āļ›็āļ™āļ•้āļ­āļ‡āļĄีāļāļēāļĢāļ–ูāļāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ่āļ­āļ™ āļāļēāļĢāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āđ„āļ§āļĢัāļŠāļ™ั้āļ™āļŠ่āļ§āļ™āđƒāļŦāļ่āļˆāļ°āđ€āļĢิ่āļĄāļ•้āļ™āļˆāļēāļāļœู้āđƒāļŠ้āļ‡āļēāļ™āļ—āļģāļāļēāļĢāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ­āļēāļˆ āļˆāļ°āđ‚āļ”āļĒāļ•ั้āļ‡āđƒāļˆāļŦāļĢืāļ­āđ„āļĄ่āļ็āļ•āļēāļĄ āļˆāļēāļāļ™ั้āļ™āđ„āļ§āļĢัāļŠāđ€āļ­āļ‡āļ็āļˆāļ°āđƒāļŠ้āđ€āļ—āļ„āļ™ิāļ„āļ­ื่āļ™āđ† āđ€āļžื่āļ­āđƒāļŦ้āļĄั่āļ™āđƒāļˆāļ§่āļēāđ„āļ”้āļ–ูāļāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ­āļĒ่āļēāļ‡āļ™้āļ­āļĒāļŦāļ™ึ่āļ‡āļ„āļĢั้āļ‡āđƒāļ™āļ—ุāļāđ† āļĢāļ°āļšāļš āđ‚āļ”āļĒāļˆāļ°āļ™āļģāļ•ัāļ§āļĄัāļ™āđ€āļ­āļ‡āđ„āļ›āđ„āļ§้āđƒāļ™āļŠ่āļ§āļ™āļ—ี่āđƒāļŠ้āđƒāļ™āļāļēāļĢāđ€āļĢิ่āļĄāļ•้āļ™āļ—āļģāļ‡āļēāļ™āļ‚āļ­āļ‡āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢ āļ‚ั้āļ™āļ•āļ­āļ™āļ™ี้āļ–ืāļ­āļ§่āļēāđ€āļ›็āļ™āļ‚ั้āļ™āļ•āļ­āļ™āļ—ี่āļ„่āļ­āļ™āļ‚้āļēāļ‡āļˆāļ°āļŠāļģāļ„ัāļāļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠāđƒāļ™āļāļēāļĢāļ—ี่āļˆāļ°āļ–ูāļ āđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ•āļĨāļ­āļ”āđ€āļ§āļĨāļēāđāļĨāļ°āļŠ่āļ‡āļœāļĨāļ•่āļ­āļāļēāļĢāļัāļ‡āļ•ัāļ§āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģ āļĒัāļ‡āļĄีāđ€āļ—āļ„āļ™ิāļ„āļ­ื่āļ™āđ† āļ—ี่āđ„āļ§āļĢัāļŠāđƒāļŠ้āđƒāļ™āļāļēāļĢāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ•ัāļ§āđ€āļ­āļ‡āđāļĨāļ°āļัāļ‡āļ­āļĒู่āđƒāļ™āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāļ™āļ­āļāđ€āļŦāļ™ืāļ­āļˆāļēāļāļ§ิāļ˜ี āļ™ี้

    āđ€āļ—āļ„āļ™ิāļ„āļŦāļ™ึ่āļ‡āļ—ี่āļ™ิāļĒāļĄāđƒāļŠ้āđƒāļ™āļĒุāļ„āđāļĢāļāđ† āļ็āļ„ืāļ­āđ„āļ§āļĢัāļŠāļˆāļ°āļ•ิāļ”āđƒāļ™āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āđƒāļŠ้āđāļ›āļĨāļ„āļģāļŠั่āļ‡ (Command Interpreter) āļ‹ึ่āļ‡āļŠ่āļ§āļ™āđƒāļŦāļ่āļˆāļ°āļĢู้āļˆัāļāđƒāļ™āļŠื่āļ­āļ‚āļ­āļ‡ command.com āđƒāļ™āļāļēāļĢāļ•ิāļ”āļ—ี่āđ„āļŸāļĨ์āļ™ี้āļĢัāļšāļĢāļ­āļ‡āđ„āļ”้āđ€āļĨāļĒāļ§่āļēāđ„āļ§āļĢัāļŠāļ™ั้āļ™āļˆāļ°āļ–ูāļāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āđāļĨāļ°āļัāļ‡āļ•ัāļ§āđƒāļ™ āļŦāļ™่āļ§āļĒāļ„āļ§āļēāļĄāļˆāļģāļ่āļ­āļ™āļ—ี่āđ‚āļ›āļĢāđāļāļĢāļĄāđāļ›āļĨāļ„āļģāļŠั่āļ‡āļˆāļ°āļ–ูāļāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āđāļ™่āļ™āļ­āļ™ āļˆāļēāļāļ™ั้āļ™āđ€āļžื่āļ­āđƒāļŦ้āļšāļĢāļĢāļĨุāđ€āļ›้āļēāļŦāļĄāļēāļĒ āđ„āļ§āļĢัāļŠāļˆāļ°āđ€āļžิ่āļĄāļ•ัāļ§āđ€āļ­āļ‡āđƒāļ™āđ„āļŸāļĨ์ autoexec.bat āļŦāļĢืāļ­ config.sys āļ‹ึ่āļ‡āđ€āļ›็āļ™āđ„āļŸāļĨ์āļ—ี่āđ€āļ็āļšāļ„่āļēāļāļēāļĢāļ›āļĢัāļšāđāļ•่āļ‡āļ–ูāļāđƒāļŠ้āđƒāļ™āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢ DOS āđāļĨāļ°āļ–ูāļāđƒāļŠ้āđƒāļ™āļāļēāļĢāđ€āļĢิ่āļĄāļ•้āļ™āļāļēāļĢāđƒāļŠ้āļ‡āļēāļ™āļžื้āļ™āļāļēāļ™āļ‚āļ­āļ‡āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์āļ”้āļ§āļĒ

    āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์

    āļ•่āļ­āļĄāļēāđ„āļ§āļĢัāļŠāđ„āļ”้āļžāļšāļŠ่āļ­āļ‡āļ—āļēāļ‡āđƒāļŦāļĄ่āđƒāļ™āļāļēāļĢāļ—ี่āļˆāļ°āļัāļ‡āļ•ัāļ§āđ€āļ­āļ‡āļ­āļĒู่āđƒāļ™āļĢāļ°āļšāļšāđāļĨāļ°āļˆāļ°āļ–ูāļ āđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ­āļĒ่āļēāļ‡āđāļ™่āļ™āļ­āļ™ āļ§ิāļ˜ีāļāļēāļĢāļ™ี้āļ„ืāļ­āļāļēāļĢāđāļ้āđ„āļ‚āļ„่āļēāđƒāļ™āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์ āļ‹ึ่āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āđ€āļ›็āļ™āļŠ่āļ§āļ™āļ—ี่āđ€āļ็āļšāļ„่āļēāđƒāļ™āļāļēāļĢāđ€āļĢิ่āļĄāļ•้āļ™āđƒāļŠ้āļ‡āļēāļ™āđāļĨāļ°āļ„่āļēāļāļēāļĢāļ›āļĢัāļšāđāļ•่āļ‡ āļ•่āļēāļ‡āđ† āļĢāļ§āļĄāļ—ั้āļ‡āļĨิ้āļ‡āļ„์āļ•่āļēāļ‡āđ† āļ‚āļ­āļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āļ•้āļ­āļ‡āļāļēāļĢāļ–ูāļāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์ āļ”ัāļ‡āļ™ั้āļ™āļ•āļģāđāļŦāļ™่āļ‡āļ™ี้āđ€āļ­āļ‡āđ€āļ›็āļ™āļ•āļģāđāļŦāļ™่āļ‡āļ—ี่āđ€āļŦāļĄāļēāļ°āļŠāļĄāļŠāļģāļŦāļĢัāļšāđ„āļ§āļĢัāļŠāļ—ี่āļˆāļ°āļ—āļģāļāļēāļĢāļัāļ‡āļ•ัāļ§āđ€āļ­āļ‡ āđƒāļŠ่āđƒāļ™āļĢāļ°āļšāļšāđ„āļ”้

    āļāļēāļĢāļ„้āļ™āļŦāļēāļ§่āļēāļĄีāđ„āļ§āļĢัāļŠāđāļ­āļšāđāļāļ‡āļ•ัāļ§āļ­āļĒู่āđƒāļĢāđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļŦāļĢืāļ­āđ„āļĄ่ āļ™ั้āļ™āļˆāļ°āđ€āļĢิ่āļĄāļ•้āļ™āļ”้āļ§āļĒāļāļēāļĢāđ€āļĢีāļĒāļāđƒāļŠ้āļ‡āļēāļ™āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āđƒāļŠ้āđāļ้āđ„āļ‚āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์ āđ‚āļ”āļĒāļāļ”āļ—ี่āļ›ุ่āļĄ Start -> Run āļˆāļ°āļ›āļĢāļēāļāļāđ„āļ”āļ­āļ°āļĨ็āļ­āļāļ‚ึ้āļ™ āļ”ัāļ‡āļĢูāļ›āļ—ี่ 3 āļˆāļēāļāļ™ั้āļ™āđƒāļŦ้āļžิāļĄāļž์āļ„āļģāļ§่āļē regedit āđƒāļ™āļŠ่āļ­āļ‡ Open: āđāļĨ้āļ§āđ€āļĨืāļ­āļāļ›ุ่āļĄ OK āļˆāļēāļāļ‚ั้āļ™āļ•āļ­āļ™āļ™ี้āļˆāļ°āļ›āļĢāļēāļāļāļŦāļ™้āļēāļ•่āļēāļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āđƒāļŠ้āđāļ้āđ„āļ‚āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļŠื่āļ­ regedit āļ”ัāļ‡āļĢูāļ›āļ—ี่ 4

    āļŦāļĄāļēāļĒāđ€āļŦāļ•ุ āļāļēāļĢāđāļ้āđ„āļ‚āļ„่āļēāđƒāļ™āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ„āļĨ้āļēāļĒāļัāļšāļāļēāļĢāļĒุāļ•ิāļāļēāļĢāļ—āļģāļ‡āļēāļ™āļ‚āļ­āļ‡āđ‚āļžāļĢāđ€āļ‹āļŠāļ—ี่āđ„āļ”้āļāļĨ่āļēāļ§āļĄāļēāļ‚้āļēāļ‡ āļ•้āļ™āđāļĨ้āļ§ āļ‹ึ่āļ‡āļāļēāļĢāđāļ้āđ„āļ‚āļ™ั้āļ™āļ­āļēāļˆāļˆāļ°āļ™āļģāļĄāļēāļ‹ึ่āļ‡āļ›ัāļāļŦāļēāļ‚āļ­āļ‡āļĢāļ°āļšāļšāļ—ี่āđ„āļĄ่āļ•้āļ­āļ‡āļāļēāļĢ āđ€āļŠ่āļ™āļāļēāļĢāđāļ้āđ„āļ‚āđ€āļžีāļĒāļ‡āđ€āļĨ็āļāļ™้āļ­āļĒāļ­āļēāļˆāļˆāļ°āļ—āļģāđƒāļŦ้āļĢāļ°āļšāļšāđ„āļĄ่āļŠāļēāļĄāļēāļĢāļ–āļ—ี่āļˆāļ°āđƒāļŠ้āļ‡āļēāļ™āđ„āļ”้āļŦāļĢืāļ­āļšูāļ•āđ„āļ”้ āļ™ั่āļ™āđ€āļ­āļ‡ āđāļĨāļ°āđƒāļ™āļšāļēāļ‡āļ„āļĢั้āļ‡āļ­āļēāļˆāļˆāļ°āļ—āļģāđƒāļŦ้āļšāļēāļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāđ„āļĄ่āļŠāļēāļĄāļēāļĢāļ–āđƒāļŠ้āļ‡āļēāļ™āđ„āļ”้ āļ”ัāļ‡āļ™ั้āļ™āļ่āļ­āļ™āļ—ี่āļˆāļ°āļ—āļģāļāļēāļĢāđāļ้āđ„āļ‚āļ„่āļēāđƒāļ™āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ—ุāļāļ„āļĢั้āļ‡ āļ•้āļ­āļ‡āļ—āļģāļāļēāļĢāļŠāļģāļĢāļ­āļ‡āļ‚้āļ­āļĄูāļĨāđ„āļ§้āļ่āļ­āļ™ āđāļĨāļ°āļˆāļ°āļ•้āļ­āļ‡āļ”āļģāđ€āļ™ิāļ™āļāļēāļĢāļ”้āļ§āļĒāļ„āļ§āļēāļĄāļĢāļ°āļĄัāļ”āļĢāļ°āļ§ัāļ‡

    āļĢูāļ›āļ—ี่ 3 āđ„āļ”āļ­āļ°āļĨ็āļ­āļāđƒāļŠ้āđƒāļ™āļāļēāļĢāđ€āļĢีāļĒāļāļĢัāļ™āđ‚āļ›āļĢāđāļāļĢāļĄāđƒāļ”āđ†

    āļĢูāļ›āļ—ี่ 4 āļŦāļ™้āļēāļ•่āļēāļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāđāļ้āđ„āļ‚āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļŠื่āļ­ regedit

    āđƒāļ™āđ‚āļ›āļĢāđāļāļĢāļĄ regedit āļ™ั้āļ™ āļ„่āļēāđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ„ีāļĒ์ (Registry keys) āļˆāļ°āļ­āļĒู่āđƒāļ™āļ„āļ­āļĨัāļĄāļ™์āļ—āļēāļ‡āļ”้āļēāļ™āļ‹้āļēāļĒāļĄืāļ­āļ—ี่āļĄีāļĨัāļāļĐāļ“āļ°āļ„āļĨ้āļēāļĒāđ† āļัāļšāđ‚āļ„āļĢāļ‡āļŠāļĢ้āļēāļ‡āļ‚āļ­āļ‡āđ„āļŸāļĨ์āđāļĨāļ°āđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์āđƒāļ™āđ‚āļ›āļĢāđāļāļĢāļĄ Windows Explorer āđƒāļ™āļ•āļģāđāļŦāļ™่āļ‡ \HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion āļˆāļ°āļĄี 3-6 āđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์āļ­āļĒู่āđƒāļ™āļ™ั้āļ™ āļ—ี่āđ€āļ›็āļ™āļŠ่āļ§āļ™āļ—ี่āđƒāļŠ้āđƒāļ™āļāļēāļĢāđ€āļĢิ่āļĄāļ•้āļ™āđƒāļŠ้āļ‡āļēāļ™āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āđ‚āļ”āļĒāļ­ัāļ•āđ‚āļ™āļĄัāļ•ิ āļĄีāļ”ัāļ‡āļ™ี้

    "Run"
    "RunOnce"
    "RunOnce\Setup"
    "RunOnceEx"
    "RunServices"
    "RunServicesOnce"

    āļ‹ึ่āļ‡āđāļ­āļžāļžāļĨิāđ€āļ„āļŠัāļ™āļ•่āļēāļ‡āđ† āļ—ี่āļ­āļĒู่āđƒāļ™āđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์āđ€āļŦāļĨ่āļēāļ™ี้āļˆāļ°āļ–ูāļāļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์āđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āļ—ัāļ™āļ—ีāļ—ี่ āļĢāļ°āļšāļšāđ€āļĢิ่āļĄāļ•้āļ™āđƒāļŠ้āļ‡āļēāļ™ āļ™āļ­āļāļˆāļēāļāļ™ี้āđāļĨ้āļ§āļ­ีāļāļ•āļģāđāļŦāļ™่āļ‡āļ—ี่āļĄี 3-6 āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ—ี่āđ€āļĢิ่āļĄāļ•้āļ™āđƒāļŠ้āļ‡āļēāļ™āđ‚āļ”āļĒāļ­ัāļ•āđ‚āļ™āļĄัāļ•ิāļ„ืāļ­āđƒāļ™āļ•āļģāđāļŦāļ™่āļ‡ \HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion

    āđ€āļĄื่āļ­āđ€āļ‚้āļēāļ–ึāļ‡āļ•āļģāđāļŦāļ™่āļ‡āļ‚āļ­āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ„ีāļĒ์āļ—ี่āđ„āļ”้āļāļĨ่āļēāļ§āļĄāļēāđāļĨ้āļ§ āđƒāļŦ้āļŠัāļ‡āđ€āļāļ•āļˆāļģāļ™āļ§āļ™āđāļ­āļžāļžāļĨิāđ€āļ„āļŠัāļ™āļ—ี่āļ­āļĒู่āđƒāļ™āļ™ั้āļ™āđ€āļ›āļĢีāļĒāļšāđ€āļ—ีāļĒāļšāļัāļšāļˆāļģāļ™āļ§āļ™āđāļ­āļžāļžāļĨิāđ€āļ„āļŠัāļ™āļ—ี่ āļ–ูāļāđ€āļ›ิāļ”āđ€āļĄื่āļ­āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāđ€āļĢิ่āļĄāļ•้āļ™āđƒāļŠ้āļ‡āļēāļ™ āđ‚āļ”āļĒāļ”ูāļˆāļēāļāļˆāļģāļ™āļ§āļ™āđ„āļ­āļ„āļ­āļ™āļ—ี่āļ­āļĒู่āđƒāļ™ system tray

    āļŦāļĄāļēāļĒāđ€āļŦāļ•ุ system tray āļ­āļĒู่āļšāļĢิāđ€āļ§āļ“āļĄุāļĄāļĨ่āļēāļ‡āļ”้āļēāļ™āļ‚āļ§āļēāļĄืāļ­āļ‚āļ­āļ‡āļŦāļ™้āļēāļˆāļ­āļ§ิāļ™āđ‚āļ”āļ§āļŠ์āļ‚้āļēāļ‡āļ™āļēāļŽิāļāļē āđāļĨāļ°āļˆāļ°āļĄีāđ„āļ­āļ„āļ­āļ™āđ€āļĨ็āļāđ† āļ­āļĒู่āđƒāļ™āļ™ั้āļ™

    āļ–้āļēāđƒāļ™āđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์ \HKEY_LOCAL_MACHINE\SOFTWARE\ āļ›āļĢāļ°āļāļ­āļšāļ”้āļ§āļĒāđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์āļ‚āļ­āļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāļ—ี่āļ™่āļēāļŠāļ‡āļŠัāļĒ āđ€āļŠ่āļ™āļŠāļ°āļāļ”āļŠื่āļ­āļšāļĢิāļĐัāļ—āļœิāļ”āđ† āļŦāļĢืāļ­āļœิāļ”āļŦāļĨัāļāđ„āļ§āļĒāļāļĢāļ“์ āđƒāļŦ้āļ—āļģāļāļēāļĢāļ•āļĢāļ§āļˆāļŠāļ­āļšāļ”ูāļ§่āļēāđ‚āļ›āļĢāđāļāļĢāļĄāļ”ัāļ‡āļāļĨ่āļēāļ§āļ™ั้āļ™āđ„āļ§āļĢัāļŠāđ€āļ›็āļ™āļœู้āļ—āļģāļāļēāļĢāļ•ิāļ”āļ•ั้āļ‡āļŦāļĢืāļ­āđ„āļĄ่ āļ­āļēāļˆāļˆāļ°āļ­้āļēāļ‡āļ­ิāļ‡āļˆāļēāļāļ„ู่āļĄืāļ­āļŦāļĢืāļ­āļ„้āļ™āļŦāļēāļˆāļēāļāļ­ิāļ™āđ€āļ—āļ­āļĢ์āđ€āļ™็āļ• āđ€āļ›็āļ™āļ•้āļ™ āļ–้āļēāļĄั่āļ™āđƒāļˆāļ§่āļēāđ‚āļ›āļĢāđāļāļĢāļĄāļ™ั้āļ™āđ€āļ›็āļ™āđ„āļ§āļĢัāļŠāļˆāļĢิāļ‡āļ็āđƒāļŦ้āļ—āļģāļāļēāļĢāļĨāļšāđ‚āļ›āļĢāđāļāļĢāļĄāļ”ัāļ‡āļāļĨ่āļēāļ§āļ™ั้āļ™āļ­āļ­āļ āļˆāļēāļāđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์ āđāļ•่āļ•้āļ­āļ‡āļˆāļģāđ„āļ§้āđ€āļŠāļĄāļ­āļ§่āļēāļāļēāļĢāđāļ้āđ„āļ‚āļ„่āļēāđƒāļ™āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ­āļēāļˆāļˆāļ°āļ™āļģāļĄāļēāļ‹ึ่āļ‡āļ„āļ§āļēāļĄāđ€āļŠีāļĒāļŦāļēāļĒāļ‚āļ­āļ‡ āļĢāļ°āļšāļšāđ„āļ”้ āļ•้āļ­āļ‡āđƒāļŠ้āļ„āļ§āļēāļĄāļĢāļ°āļĄัāļ”āļĢāļ°āļ§ัāļ‡āđƒāļŦ้āļĄāļēāļ āđāļĨāļ°āļ่āļ­āļ™āļˆāļ°āđāļ้āđ„āļ‚āļ„āļ§āļĢāļ—āļģāļāļēāļĢāļŠāļģāļĢāļ­āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ”้āļ§āļĒ

    āļ­ีāļāļŦāļ™ึ่āļ‡āļŦāļ™āļ—āļēāļ‡āļ—ี่āđ„āļ§āļĢัāļŠāđƒāļŠ้āđƒāļ™āļāļēāļĢāļāļĢāļ°āļˆāļēāļĒāļ•ัāļ§āđ€āļ­āļ‡āđ„āļ”้āđ‚āļ”āļĒāļˆāļ°āđāļ้āđ„āļ‚āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ—ี่ āđ€āļี่āļĒāļ§āļ‚้āļ­āļ‡āļัāļšāļ™āļēāļĄāļŠāļุāļĨāļ‚āļ­āļ‡āđ„āļŸāļĨ์āļ—ั่āļ§āđ† āđ„āļ› āđƒāļŦ้āļĢัāļ™āļ”้āļ§āļĒāđ‚āļ›āļĢāđāļāļĢāļĄāļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠāđ€āļ­āļ‡ āļ•ัāļ§āļ­āļĒ่āļēāļ‡āļ‚āļ­āļ‡āļ™āļēāļĄāļŠāļุāļĨāļ‚āļ­āļ‡āđ„āļŸāļĨ์āļ—ั่āļ§āđ† āđ„āļ›āđ€āļŠ่āļ™ .EXE .DLL .COM āđ€āļ›็āļ™āļ•้āļ™ āļ‹ึ่āļ‡āđƒāļ™āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ§ิāļ™āđ‚āļ”āļ§āļŠ์āļ™ั้āļ™āļĄีāđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ„ีāļĒ์āļ—ี่āļŠื่āļ­ /HKEY_CLASSES_ROOT āļŠāļģāļŦāļĢัāļšāđ€āļ็āļšāļ„่āļēāļ§่āļēāđ„āļŸāļĨ์āļ—ี่āļĄีāļ™āļēāļĄāļŠāļุāļĨāđƒāļ”āđƒāļŦ้āļĢัāļ™āļ”้āļ§āļĒāđāļ­āļžāļžāļĨิāđ€āļ„āļŠัāļ™āđƒāļ” āđ€āļŠ่āļ™āđ„āļŸāļĨ์āļ—ี่āļĄีāļ™āļēāļĄāļŠāļุāļĨ .DOC āđƒāļŦ้āļĢัāļ™āļ”้āļ§āļĒāđ‚āļ›āļĢāđāļāļĢāļĄāđ„āļĄāđ‚āļ„āļĢāļ‹āļ­āļŸāļ•์āđ€āļ§ิāļĢ์āļ” (MS Word) āđ€āļ›็āļ™āļ•้āļ™

    āļāļēāļĢāļŠāļģāļĢāļ­āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ­āļĒู่āđ€āļŠāļĄāļ­āđ€āļ›็āļ™āļŦāļ™āļ—āļēāļ‡āļ—ี่āļˆāļ°āļŠ่āļ§āļĒāļู้āļĢāļ°āļšāļšāļ„ืāļ™āļŦāļĨัāļ‡āļˆāļēāļāļĢāļ°āļšāļšāļ—āļģ āļ‡āļēāļ™āļœิāļ”āļžāļĨāļēāļ”āļ­ัāļ™āđ€āļ™ื่āļ­āļ‡āļĄāļēāļˆāļēāļāļāļēāļĢāđāļ้āđ„āļ‚āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļœิāļ”āļžāļĨāļēāļ” āļ—ั้āļ‡āļ™ี้āļ­āļēāļˆāļˆāļ°āļĄีāļŠāļēāđ€āļŦāļ•ุāļˆāļēāļāđ„āļ§āļĢัāļŠāđāļ้āđ„āļ‚āđ€āļ­āļ‡āļŦāļĢืāļ­āļœู้āđƒāļŠ้āđ€āļ›็āļ™āļœู้āđāļ้āđ„āļ‚āđ€āļ­āļ‡ āļ§ิāļ˜ีāļāļēāļĢāđƒāļ™āļāļēāļĢāļŠāļģāļĢāļ­āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āđ‚āļ”āļĒāļāļēāļĢāļŠ่āļ‡āļ„่āļēāđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ­āļ­āļāļĄāļēāđ€āļ็āļšāđ„āļ§้āđ€āļ›็āļ™āđ„āļŸāļĨ์ āļŦāļĢืāļ­āđ€āļĢีāļĒāļāļ§่āļēāļāļēāļĢ export āļ™ั่āļ™āđ€āļ­āļ‡ āļ—āļģāđ„āļ”้āđ‚āļ”āļĒāđ€āļĨืāļ­āļāđ€āļĄāļ™ู Registry -> Export Registry File āļ”ัāļ‡āļĢูāļ›āļ—ี่ 5 āļˆāļ°āļ›āļĢāļēāļāļāđ„āļ”āļ­āļ°āļĨ็āļ­āļāļ”ัāļ‡āļĢูāļ›āļ—ี่ 6 āļˆāļēāļāļ™ั้āļ™āļˆึāļ‡āļ—āļģāļāļēāļĢāļ›้āļ­āļ™āļŠื่āļ­āļ—ี่āļˆāļ°āļšัāļ™āļ—ึāļāđāļĨ้āļ§āļāļ” Save āđ€āļ›็āļ™āļ­ัāļ™āđ€āļŠāļĢ็āļˆāļ‚ั้āļ™āļ•āļ­āļ™āļāļēāļĢāļŠāļģāļĢāļ­āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์ āđ€āļĄื่āļ­āļ—āļģāļāļēāļĢāļŠāļģāļĢāļ­āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āđāļĨ้āļ§āļāļēāļĢāđ€āļĢีāļĒāļāđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์āļ—ี่āļŠāļģāļĢāļ­āļ‡āđ„āļ§้āļĄāļēāđƒāļŠ้āļ‡āļēāļ™āļ—āļģāđ„āļ”้ āđ‚āļ”āļĒāđ€āļĨืāļ­āļāđ€āļĄāļ™ู Registry -> Import Registry File āļ”ัāļ‡āļĢูāļ›āļ—ี่ 7 āđāļĨāļ°āļˆāļ°āļ›āļĢāļēāļāļāđ„āļ”āļ­āļ°āļĨ็āļ­āļāļ”ัāļ‡āļĢูāļ›āļ—ี่ 8 āđāļĨ้āļ§āđ€āļĨืāļ­āļāđ„āļŸāļĨ์āļ—ี่āļ•้āļ­āļ‡āļāļēāļĢāļˆāļ°āđ€āļĢีāļĒāļāđƒāļŠ้ āļˆāļēāļāļ™ั้āļ™āļˆึāļ‡āļāļ”āļ›ุ่āļĄ Open

    āļĢูāļ›āļ—ี่ 5 āđāļŠāļ”āļ‡āļāļēāļĢ Export āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์

    āļĢูāļ›āļ—ี่ 6 āđāļŠāļ”āļ‡āđ„āļ”āļ­āļ°āļĨ็āļ­āļāđ€āļžื่āļ­āđ€āļĨืāļ­āļāđ„āļŸāļĨ์āļ—ี่āļˆāļ°āđƒāļŠ้āļŠāļģāļĢāļ­āļ‡āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์

    āļĢูāļ›āļ—ี่ 7 āđāļŠāļ”āļ‡āļ§ิāļ˜ีāļāļēāļĢ Import āđ€āļĢāļˆิāļŠāļ—āļĢีāļĒ์

    āļĢูāļ›āļ—ี่ 8 āđāļŠāļ”āļ‡āđ„āļ”āļ­āļ°āļĨ็āļ­āļāđ€āļžื่āļ­āđ€āļĨืāļ­āļāđƒāļŠ้āđ„āļŸāļĨ์āđƒāļ™āļāļēāļĢāļู้āļĢāļ°āļšāļšāļ„ืāļ™

    āļ•āļģāđāļŦāļ™่āļ‡ StartUp āļ­ื่āļ™āđ†

    āļˆāļēāļāļ—ี่āđ„āļ”้āļāļĨ่āļēāļ§āļĄāļēāđƒāļ™āļ‚้āļēāļ‡āļ•้āļ™āđāļĨ้āļ§ āļĒัāļ‡āļĄีāļ•āļģāđāļŦāļ™่āļ‡āļ­ื่āļ™āđ† āļ—ี่āđ„āļ§āļĢัāļŠāļĄัāļāļ™ิāļĒāļĄāđƒāļŠ้āđƒāļ™āļāļēāļĢāđ€āļĢิ่āļĄāļ—āļģāļ‡āļēāļ™ āđ€āļŠ่āļ™āđƒāļ™āđ„āļŸāļĨ์ System.ini āđāļĨāļ° Win.ini āđ„āļ§āļĢัāļŠāļˆāļ°āđāļ้āđ„āļ‚āđ„āļŸāļĨ์āđ€āļŦāļĨ่āļēāļ™ี้āļ—ี่āļ­āļĒู่āđƒāļ™āđ„āļ”āđ€āļĢāļāļ—āļ­āļĢีāļ‚āļ­āļ‡āļ§ิāļ™āđ‚āļ”āļ§āļŠ์ (āđ€āļŠ่āļ™ %Windows% āļŦāļĢืāļ­ %Winnt%) āđ‚āļ”āļĒāđ„āļ§āļĢัāļŠāļˆāļ°āđ€āļžิ่āļĄāļšāļĢāļĢāļ—ัāļ”āļ—ี่āļšāļ­āļāļ§่āļē "run=āļŠื่āļ­ āđ‚āļ›āļĢāđāļāļĢāļĄāļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠ" āļŦāļĢืāļ­ "load=āļŠื่āļ­ āđ‚āļ›āļĢāđāļāļĢāļĄāļ‚āļ­āļ‡āđ„āļ§āļĢัāļŠ"

    āļ„่āļēāļāļēāļĢāļ›āļĢัāļšāđāļ•่āļ‡āļ—ี่āļŠāļģāļ„ัāļāļ•่āļ­āļĢāļ°āļšāļšāļŠāļēāļĄāļēāļĢāļ–āđāļ้āđ„āļ‚āđ„āļ”้āļ”้āļ§āļĒāđ‚āļ›āļĢāđāļāļĢāļĄ Sysedit āļĄีāļ§ิāļ˜ีāļāļēāļĢāđ€āļĢีāļĒāļāđƒāļŠ้āļ‡āļēāļ™āđ‚āļ”āļĒāļāļ”āļ›ุ่āļĄ Start -> run āļˆāļēāļāļ™ั้āļ™āļ›้āļ­āļ™āļ„āļģāļ§่āļē "sysedit" āđƒāļ™āļŠ่āļ­āļ‡ Open: āđāļĨ้āļ§āļāļ”āļ›ุ่āļĄ OK āļˆāļ°āļ›āļĢāļēāļāļāļŦāļ™้āļēāļ•่āļēāļ‡āļ”ัāļ‡āļĢูāļ›āļ—ี่ 9

    āļŦāļĄāļēāļĒāđ€āļŦāļ•ุ āļāļēāļĢāļ›āļĢัāļšāđāļ•่āļ‡āļ„่āļēāļ•่āļēāļ‡āđ† āđ‚āļ”āļĒāđƒāļŠ้āđ‚āļ›āļĢāđāļāļĢāļĄ Sysedit āļ„āļ§āļĢāļ—ี่āļˆāļ°āļŠāļģāļĢāļ­āļ‡āļ‚้āļ­āļĄูāļĨāļ‚āļ­āļ‡āđāļ•่āļĨāļ°āđ„āļŸāļĨ์āļ่āļ­āļ™āļ—ุāļāļ„āļĢั้āļ‡

    āļĢูāļ›āļ—ี่ 9 āđāļŠāļ”āļ‡āđ‚āļ›āļĢāđāļāļĢāļĄ Sysedit

    āļ™āļ­āļāļˆāļēāļāļ™ี้āļĒัāļ‡āļĄีāđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์āļ—ี่āđƒāļŦ้āļĢāļ°āļšāļšāļ›āļิāļšัāļ•ิāļāļēāļĢāļ—āļģāļāļēāļĢāđ€āļ­็āļāļ‹ิāļ„ิāļ§āļ•์āđāļ­āļžāļžāļĨิāđ€āļ„ āļŠั่āļ™āļ—ี่āļ­āļĒู่āđƒāļ™āđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์āļ™ี้āļ—ุāļāļ„āļĢั้āļ‡āļ—ี่āļĢāļ°āļšāļšāđ€āļĢิ่āļĄāļ—āļģāļ‡āļēāļ™ āđ‚āļŸāļĨ์āđ€āļ”āļ­āļĢ์āļ”ัāļ‡āļāļĨ่āļēāļ§āļ™ั้āļ™āđ€āļ‚้āļēāļ–ึāļ‡āđ„āļ”้āđ‚āļ”āļĒ Start -> (All) Programs -> Startup āļ–้āļēāļĄีāđāļ­āļžāļžāļĨิāđ€āļ„āļŠั่āļ™āļ—ี่āđ„āļĄ่āđ„āļ”้āđƒāļŠ้āļ‡āļēāļ™āļŦāļĢืāļ­āđāļ­āļžāļžāļĨิāđ€āļ„āļŠั่āļ™āļ—ี่āļ™่āļēāļŠāļ‡āļŠัāļĒāļ§่āļēāđ€āļ›็āļ™āđ„āļ§āļĢัāļŠ āļ­āļĒู่āđƒāļ™āđ‚āļŸāļĨāđ€āļ”āļ­āļĢ์āļ™ี้āđƒāļŦ้āļ—āļģāļāļēāļĢāļĨāļšāđ„āļ”้āļ—ัāļ™āļ—ี

    āļ§ิāļ˜ีāļāļēāļĢāļ•āļĢāļ§āļˆāļŦāļēāđ„āļ§āļĢัāļŠāļ—ี่āđ„āļ”้āļāļĨ่āļēāļ§āļĄāļēāļ—ั้āļ‡āļŦāļĄāļ”āļ™ั้āļ™ āļ„āļ§āļĢāļĻึāļāļĐāļēāđƒāļŦ้āđ€āļ‚้āļēāđƒāļˆāđāļĨāļ°āļึāļāļāļ™āļ­āļĒู่āđ€āļŠāļĄāļ­āđ€āļžื่āļ­āđƒāļŦ้āđ€āļิāļ”āļ„āļ§āļēāļĄāļŠāļģāļ™āļēāļ āđāļĨāļ°āļ—ี่āļŠāļģāļ„ัāļāļ„ืāļ­āļˆāļ°āļ•้āļ­āļ‡āļ—āļģāļāļēāļĢāļ›้āļ­āļ‡āļัāļ™āļ•ัāļ§āđ€āļ­āļ‡āđƒāļŦ้āļ›āļĨāļ­āļ”āļ ัāļĒāļˆāļēāļāđ„āļ§āļĢัāļŠāļ”้āļ§āļĒāļ§ิāļ˜ีāļāļēāļĢāļ•่āļēāļ‡āđ† āđ€āļŠ่āļ™āļāļēāļĢāļ­ัāļžāđ€āļ”āļ•āđ‚āļ›āļĢāđāļāļĢāļĄāļ•่āļēāļ‡āđ† āļ—ี่āđƒāļŠ้āļ‡āļēāļ™ āļ•āļĨāļ­āļ”āļˆāļ™āļ­ัāļžāđ€āļ”āļ•āļāļēāļ™āļ‚้āļ­āļĄูāļĨāļ‚āļ­āļ‡āđ‚āļ›āļĢāđāļāļĢāļĄāļ›้āļ­āļ‡āļัāļ™āđ„āļ§āļĢัāļŠ āđ€āļ›็āļ™āļ•้āļ™

    āļ­้āļēāļ‡āļ­ิāļ‡

    http://www.securityfocus.com/infocus/1666http://news.zdnet.co.uk/cgi-bin/uk/printer_friendly.cgi?id=2085274http://www.itsecurity.com/tutor/howtodetectavirus.htm

    Wednesday, March 3, 2010

    āđ‚āļ›āļĢāđāļāļĢāļĄāļĨāļšāđ„āļ§āļĢัāļŠ sxs.exe

    āđ‚āļ›āļĢāđāļāļĢāļĄāļĨāļšāđ„āļ§āļĢัāļŠ sxs.exe

    āđ‚āļ›āļĢāđāļāļĢāļĄ āļ™ี้āļˆāļ°āļāļģāļˆัāļ”āđ„āļ§āļĢัāļŠ sxs.exe āđƒāļ™āđāļŪāļ™āļ”ี้āđ„āļ”āļĢ์āļ§āđāļĨāļ°āļšāļ™āđ€āļ„āļĢื่āļ­āļ‡āļ—ี่āļ•ิāļ”āđ€āļŠื้āļ­ āļ‹ึ่āļ‡āđ„āļ§āļĢัāļŠāļ•ัāļ§āļ™ี้āļˆāļ°āļŠāļĢ้āļēāļ‡āđ„āļŸāļĨ์ auto run āļĨāļ‡āđƒāļ™āļ—ุāļāđ†āđ„āļ”āļĢ์āļ§āđ€āļžื่āļ­āđ€āļĢีāļĒāļāļ•ัāļ§āđ€āļ­āļ‡āļ‚ึ้āļ™āļ—āļģāļ‡āļēāļ™āļ—ุāļāļ„āļĢั้āļ‡āļ—ี่āļĄีāļāļēāļĢāļ”ัāļšāđ€āļšิāļĨāļ„āļĨิāļ āļ—ี่āđ„āļ”āļĢ์āļ§āļ™ั้āļ™āđ† āđ„āļ§āļĢัāļŠāļˆāļ°āļ—āļģāļāļēāļĢāļ›āļĢัāļšāđāļ•่āļ‡āđ€āļ„āļĢื่āļ­āļ‡āđ€āļŦāļĒื่āļ­āđ‚āļ”āļĒāđƒāļŠ้āđ‚āļ›āļĢāđāļāļĄ net.exe āđāļĨāļ° sc.exe āļĒัāļ‡āđ„āļĄ่āđāļ™่āđƒāļˆāļ§่āļēāļĄัāļ™āļ—āļģāļ­āļ°āđ„āļĢāđ€āļžāļĢāļēāļ°āļœู้āđ€āļ‚ีāļĒāļ™āđ„āļ§āļĢัāļŠāđ„āļ”้āđ€āļ‚้āļēāļĢāļŦัāļŠāđ„āļŸāļĨ์āđ„āļ§้ āļ—āļģāđƒāļŦ้āļĒāļēāļāļ•่āļ­āļāļēāļĢāļ—āļģāļ„āļ§āļēāļĄāđ€āļ‚้āļēāđƒāļˆāđ‚āļ„้āļ”āđƒāļ™āđ„āļŸāļĨ์āđ„āļ§āļĢัāļŠ āļ­āļēāļāļēāļĢāđ€āļ„āļĢื่āļ­āļ‡āļ—ี่āļ•ิāļ”āļ็āļ„ืāļ­āļˆāļ°āļ”ัāļšāđ€āļšิāļĨāļ„āļĨิāļāđ€āļ›ิāļ”āđ€āļ‚้āļēāđ„āļ”āļĢ์āļ§āļ•่āļēāļ‡āđ† āđ„āļĄ่āđ„āļ”้ āđāļ•่āļŠāļēāļĄāļēāļĢāļ–āđ€āļ‚้āļē āđƒāļŠ้āļ‡āļēāļ™āđ„āļ”āļĢ์āļ§ C:āđ„āļ”้ āļāļēāļĢāļāļģāļˆัāļ”āļŠāļēāļĄāļēāļĢāļ–āđ€āļŠื่āļ­āļĄāļ•่āļ­āđāļŪāļ™āļ”ี้āđ„āļ”āļĢ์āļ§āļ—ี่āļ•้āļ­āļ‡āļŠāļ‡āļŠัāļĒāđ€āļ‚้āļēāļัāļšāđ€āļ„āļĢื่āļ­āļ‡āđāļĨ้āļ§āļĢัāļ™āļ•ัāļ§ āđāļ้āđ€āļžื่āļ­āļāļģāļˆัāļ”āđ„āļ§āļĢัāļŠāļšāļ™āđ€āļ„āļĢื่āļ­āļ‡āđāļĨāļ°āđƒāļ™āđāļŪāļ™āļ”ี้āđ„āļ”āļĢ์āļ§āļžāļĢ้āļ­āļĄāđ†āļัāļ™āđ„āļ”้ āļ”āļēāļ§āļ™์āđ‚āļŦāļĨāļ”āļ•ัāļ§āđāļ้āđ„āļ”้āļ—ี่āļ™ี่āļ„āļĢัāļš

    Download
    * SXS_Killer.zip